#securityresearch — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #securityresearch, aggregated by home.social.
-
i just published codex tripwire.
it runs alongside codex cli and gives you a live audit view of executed commands, mcp calls, web searches and sandbox network activity, including allow/block decisions and session correlation. everything stays local.
https://github.com/moltenbit/codex-tripwire
#codex #opensource #cybersecurity #infosec #securityresearch
-
i just published codex tripwire.
it runs alongside codex cli and gives you a live audit view of executed commands, mcp calls, web searches and sandbox network activity, including allow/block decisions and session correlation. everything stays local.
https://github.com/moltenbit/codex-tripwire
#codex #opensource #cybersecurity #infosec #securityresearch
-
This is the part of 2FA/TOTP that many people don’t realize:
Your phone isn’t receiving the 6-digit code from the server.
Instead, your authenticator app acts like a specialized cryptographic calculator. 🧮🔐
It takes a shared secret key, combines it with the current time, and applies the TOTP algorithm to generate a temporary 6-digit code.
At the same time, the server independently performs the same calculation using its copy of the secret key and the same time counter.
Same secret + same time counter + same algorithm = same result.
That’s why your authenticator app can generate the correct code without receiving it from the server.
It’s a simple idea, but a brilliant application of cryptography.
You can even test this yourself: add the same TOTP secret to both Google Authenticator and Microsoft Authenticator. Even if you set them up at different times, both apps can independently generate the same 6-digit code at the same time.
And here’s another important point:
The algorithm doesn’t need to be secret.
TOTP is based on publicly known, standardized cryptographic algorithms such as HMAC. What needs to remain secret is the shared secret key.
So:
🧮 Algorithm/math: Can be publicly known.
🔑 Secret key: Must remain private. Never share it.
⏱️ Time: Isn’t secret.
🔐 Security: Comes from protecting the secret key, not from hiding the algorithm.That’s a core principle of modern cryptography: A cryptographic system should remain secure even when the algorithm is publicly known. The secret is the key.
#2FA #TwoFactor #Security #Cybersecurity #SecretKey #Authentication #Cryptography #Math #TOTP #OTP #AuthenticatorApp #Internet #SecurityResearch
-
This is the part of 2FA/TOTP that many people don’t realize:
Your phone isn’t receiving the 6-digit code from the server.
Instead, your authenticator app acts like a specialized cryptographic calculator. 🧮🔐
It takes a shared secret key, combines it with the current time, and applies the TOTP algorithm to generate a temporary 6-digit code.
At the same time, the server independently performs the same calculation using its copy of the secret key and the same time counter.
Same secret + same time counter + same algorithm = same result.
That’s why your authenticator app can generate the correct code without receiving it from the server.
It’s a simple idea, but a brilliant application of cryptography.
You can even test this yourself: add the same TOTP secret to both Google Authenticator and Microsoft Authenticator. Even if you set them up at different times, both apps can independently generate the same 6-digit code at the same time.
And here’s another important point:
The algorithm doesn’t need to be secret.
TOTP is based on publicly known, standardized cryptographic algorithms such as HMAC. What needs to remain secret is the shared secret key.
So:
🧮 Algorithm/math: Can be publicly known.
🔑 Secret key: Must remain private. Never share it.
⏱️ Time: Isn’t secret.
🔐 Security: Comes from protecting the secret key, not from hiding the algorithm.That’s a core principle of modern cryptography: A cryptographic system should remain secure even when the algorithm is publicly known. The secret is the key.
#2FA #TwoFactor #Security #Cybersecurity #SecretKey #Authentication #Cryptography #Math #TOTP #OTP #AuthenticatorApp #Internet #SecurityResearch
-
🛡️ Exploit Database — Top Exploits by Category
Explore some of the most important vulnerabilities across major Exploit-DB categories, with CVE references, vulnerability types, and impact explained in one visual guide.
💬 Comment “EXPLOIT” if you want more cybersecurity cheat sheets like this.
#CyberSecurity #ExploitDB #InfoSec #SecurityResearch #Pentesting
-
🛡️ Exploit Database — Top Exploits by Category
Explore some of the most important vulnerabilities across major Exploit-DB categories, with CVE references, vulnerability types, and impact explained in one visual guide.
💬 Comment “EXPLOIT” if you want more cybersecurity cheat sheets like this.
#CyberSecurity #ExploitDB #InfoSec #SecurityResearch #Pentesting
-
https://winbuzzer.com/2026/07/28/nvidia-microsoft-launch-ai-security-alliance-without-openai-xcxwbn/
NVIDIA, Microsoft and 30 other partners have launched the Open Secure AI Alliance, while OpenAI, Google and Anthropic are absent from its founding roster.
#AI #NVIDIA #Microsoft #AISecurity #Cybersecurity #OpenAI #Google #Anthropic #SecurityResearch
-
https://winbuzzer.com/2026/07/28/nvidia-microsoft-launch-ai-security-alliance-without-openai-xcxwbn/
NVIDIA, Microsoft and 30 other partners have launched the Open Secure AI Alliance, while OpenAI, Google and Anthropic are absent from its founding roster.
#AI #NVIDIA #Microsoft #AISecurity #Cybersecurity #OpenAI #Google #Anthropic #SecurityResearch
-
https://winbuzzer.com/2026/07/28/github-cuts-public-bug-bounties-gates-top-rewards-xcxwbn/
GitHub has cut public bug bounty payouts on July 27, capping critical rewards at $10,000 while reserving $30,000-plus payments for invited researchers.
#AI #GitHub #BugBounties #BugBounty #HackerOne #Cybersecurity #SecurityResearch
-
https://winbuzzer.com/2026/07/28/github-cuts-public-bug-bounties-gates-top-rewards-xcxwbn/
GitHub has cut public bug bounty payouts on July 27, capping critical rewards at $10,000 while reserving $30,000-plus payments for invited researchers.
#AI #GitHub #BugBounties #BugBounty #HackerOne #Cybersecurity #SecurityResearch
-
https://winbuzzer.com/2026/07/06/ai-bug-hunters-coincide-with-record-cve-disclosures-xcxwbn/
Epoch AI data points to a record June surge in public software-flaw disclosures as AI bug-hunting expands, but the data cannot prove which flaws AI found.
#AI #SecurityVulnerabilities #Cybersecurity #SecurityResearch #OpenAI #Anthropic #ClaudeMythos #ProjectGlasswing #OpenAIDaybreak
-
https://winbuzzer.com/2026/07/06/ai-bug-hunters-coincide-with-record-cve-disclosures-xcxwbn/
Epoch AI data points to a record June surge in public software-flaw disclosures as AI bug-hunting expands, but the data cannot prove which flaws AI found.
#AI #SecurityVulnerabilities #Cybersecurity #SecurityResearch #OpenAI #Anthropic #ClaudeMythos #ProjectGlasswing #OpenAIDaybreak
-
I need followers in tech + cybersecurity—please help... I promise I’ll post stuff smarter than “oops, wrong config”.
#CyberSecurity #Infosec #ThreatIntelligence #SecurityResearch #BlueTeam #RedTeam #SOC #VulnerabilityManagement #AppSec #PenTesting #threatintel
-
New blog post!
The title should be self-explanatory, it's an appreciation post for Nightmare Eclipse.
You might notice that the tone is a bit more emotional/angry than my usual style of writing.
This one's personal.https://ti-kallisti.com/infosec/ms/nightmare-eclipse.html
#NightmareEclipse #Microsoft #Hackers #InfoSec #SecurityResearch #ChainsawMan #Reze
-
New blog post!
The title should be self-explanatory, it's an appreciation post for Nightmare Eclipse.
You might notice that the tone is a bit more emotional/angry than my usual style of writing.
This one's personal.https://ti-kallisti.com/infosec/ms/nightmare-eclipse.html
#NightmareEclipse #Microsoft #Hackers #InfoSec #SecurityResearch #ChainsawMan #Reze
-
https://winbuzzer.com/2026/06/21/pypi-malware-wave-exposes-weak-ai-scanner-boundary-xcxwbn/
PyPI Malware Wave Exposes Weak AI Malware Scanner Boundary
#AI #PyPI #Malware #AISecurity #Cybersecurity #Javascript #AISafety #AntiMalware #SecurityResearch #CyberThreats
-
https://winbuzzer.com/2026/06/21/pypi-malware-wave-exposes-weak-ai-scanner-boundary-xcxwbn/
PyPI Malware Wave Exposes Weak AI Malware Scanner Boundary
#AI #PyPI #Malware #AISecurity #Cybersecurity #Javascript #AISafety #AntiMalware #SecurityResearch #CyberThreats
-
Looking forward to #OWASP Global AppSec EU and the inaugural #MAScon next week. Excited for the opportunity to learn from researchers and practitioners who are pushing mobile security forward.
Check out some of the sessions: https://loom.ly/qC3L65o
@owasp #OWASPGlobalAppSec #MobileApps #MobileSecurity #SecurityResearch
-
Looking forward to #OWASP Global AppSec EU and the inaugural #MAScon next week. Excited for the opportunity to learn from researchers and practitioners who are pushing mobile security forward.
Check out some of the sessions: https://loom.ly/qC3L65o
@owasp #OWASPGlobalAppSec #MobileApps #MobileSecurity #SecurityResearch
-
You demonstrate a fileless RCE chain. Complex delivery, in-memory execution, zero detections, confirmed working on multiple devices.
The vendor reviews it twice, involves engineering, then tells you:
"Your research demonstrates a complex chain for delivering and executing code."
...and closes it as 'intended behavior. Not a platform vulnerability.'
Question: is it a vulnerability?
Follow-up: does your answer change if the attack surface exists *between* components — where no single owner's scope definition covers the full chain?
Asking because I have a paper dropping soon about that.
#VRP #responsibleDisclosure #semanticGap #infosec #securityResearch
-
I was tired of digging through endless random cybersecurity lists, so naturally I built another random cybersecurity list - just cleaner, prettier and actually organized.
Hack Hub is a curated directory of useful security resources.
#CyberSecurity #InfoSec #Hacking #EthicalHacking #Pentesting #RedTeam #BlueTeam #DFIR #OSINT #ThreatIntel #MalwareAnalysis #BugBounty #CloudSecurity #MobileSecurity #OpenSource #SecurityTools #SecurityResearch #Linux #Hackers #Tech
-
I was tired of digging through endless random cybersecurity lists, so naturally I built another random cybersecurity list - just cleaner, prettier and actually organized.
Hack Hub is a curated directory of useful security resources.
#CyberSecurity #InfoSec #Hacking #EthicalHacking #Pentesting #RedTeam #BlueTeam #DFIR #OSINT #ThreatIntel #MalwareAnalysis #BugBounty #CloudSecurity #MobileSecurity #OpenSource #SecurityTools #SecurityResearch #Linux #Hackers #Tech
-
https://winbuzzer.com/2026/06/03/toronto-ai-worm-prototype-tests-adaptive-malware-risk-xcxwbn/
Researchers built a contained AI powered malware worm that adapts attacks across lab hosts, exposing how local open-weight models complicate malware containment.
#AI #AIAgents #AISecurity #AIResearch #Cybersecurity #Malware #SecurityVulnerabilities #CyberThreats #SecurityResearch
-
https://winbuzzer.com/2026/06/03/toronto-ai-worm-prototype-tests-adaptive-malware-risk-xcxwbn/
Researchers built a contained AI powered malware worm that adapts attacks across lab hosts, exposing how local open-weight models complicate malware containment.
#AI #AIAgents #AISecurity #AIResearch #Cybersecurity #Malware #SecurityVulnerabilities #CyberThreats #SecurityResearch
-
https://winbuzzer.com/2026/06/02/microsoft-backs-off-threats-against-security-researchers-xcxwbn/
Microsoft has ruled out action against security researchers after a backlash, narrowing legal risk around its wider disclosure dispute.
#SecurityResearch #Microsoft #Security #Cybersecurity #ZeroDay #MicrosoftWindows #WindowsSecurity #WindowsVulnerability #Windows11
-
https://winbuzzer.com/2026/06/02/microsoft-backs-off-threats-against-security-researchers-xcxwbn/
Microsoft has ruled out action against security researchers after a backlash, narrowing legal risk around its wider disclosure dispute.
#SecurityResearch #Microsoft #Security #Cybersecurity #ZeroDay #MicrosoftWindows #WindowsSecurity #WindowsVulnerability #Windows11
-
Bug Bounty situation = Netflix & Piracy situation?
*Boosts welcome
I want to hear your opinion on an idea I had recently:
So, movies/TV piracy is rising recently. And much of it is due to the overwhelming amount of providers, and the fact that each one has a small portion of the pie.
Unlike Music, where providers have mostly the same, allowing for a good customer experience, lowering the need to pirate music, in the movies/TV industry the situation is just getting worse each day, making the rise of piracy (discussed in DarknetDiaries' episode about the magic box) bigger each day.I was wondering if the same thing would/is happening in the bug bounty world.
As more and more companies close their bug bounty programs, or lower the rewards, could researchers turn to selling their findings on the dark net/other forums alike?After all, many researchers do this to make a living, and not be a knight on a white horse.
And if someone invested months researching and testing to find a critical vulnerability, they won't be able to go shopping with a Thank You letter.what do you think?
I'm not a bug bounter so I don't really live this world, but some of you are. what do you think?
is it already happening? -
Bug Bounty situation = Netflix & Piracy situation?
*Boosts welcome
I want to hear your opinion on an idea I had recently:
So, movies/TV piracy is rising recently. And much of it is due to the overwhelming amount of providers, and the fact that each one has a small portion of the pie.
Unlike Music, where providers have mostly the same, allowing for a good customer experience, lowering the need to pirate music, in the movies/TV industry the situation is just getting worse each day, making the rise of piracy (discussed in DarknetDiaries' episode about the magic box) bigger each day.I was wondering if the same thing would/is happening in the bug bounty world.
As more and more companies close their bug bounty programs, or lower the rewards, could researchers turn to selling their findings on the dark net/other forums alike?After all, many researchers do this to make a living, and not be a knight on a white horse.
And if someone invested months researching and testing to find a critical vulnerability, they won't be able to go shopping with a Thank You letter.what do you think?
I'm not a bug bounter so I don't really live this world, but some of you are. what do you think?
is it already happening? -
Shodan Dork Cheat Sheet
In this cheat sheet, I cover useful Shodan search queries, filtering techniques, and practical reconnaissance workflows for cybersecurity assessments
https://denizhalil.com/2023/12/19/shodan-dork-cheat-sheet/#CyberSecurity #Shodan #OSINT #Reconnaissance #AttackSurface #ThreatIntelligence #Pentesting #RedTeam #InfoSec #EthicalHacking #SecurityResearch #DenizHalil
-
Shodan Dork Cheat Sheet
In this cheat sheet, I cover useful Shodan search queries, filtering techniques, and practical reconnaissance workflows for cybersecurity assessments
https://denizhalil.com/2023/12/19/shodan-dork-cheat-sheet/#CyberSecurity #Shodan #OSINT #Reconnaissance #AttackSurface #ThreatIntelligence #Pentesting #RedTeam #InfoSec #EthicalHacking #SecurityResearch #DenizHalil
-
I bypassed AWS API Gateway auth with a trailing slash. Got $12K bounty
https://theguptalog.blogspot.com/2026/04/i-bypassed-aws-api-gateway-auth-with.html
#HackerNews #AWS #API #Gateway #Bounty #TrailingSlash #SecurityResearch #Cybersecurity
-
I bypassed AWS API Gateway auth with a trailing slash. Got $12K bounty
https://theguptalog.blogspot.com/2026/04/i-bypassed-aws-api-gateway-auth-with.html
#HackerNews #AWS #API #Gateway #Bounty #TrailingSlash #SecurityResearch #Cybersecurity
-
Fuzzing finds bugs in Rust code - reliably so. But async Rust has largely stayed out of reach with its complexity making it hard for fuzzers to explore meaningfully.
At Oxidize 2026, Morgan Hill (@pcwizz) walks through what it takes to actually fuzz async Rust: the naive approaches that don't work, and an involved technique that does - involving LibAFL, user mode QEMU, and a fair amount of head scratching.
🔗 https://oxidizeconf.com/sessions/awaiting_exploitation
#Oxidize2026 #RustLang #Fuzzing #SecurityResearch #AsyncRust
-
Fuzzing finds bugs in Rust code - reliably so. But async Rust has largely stayed out of reach with its complexity making it hard for fuzzers to explore meaningfully.
At Oxidize 2026, Morgan Hill (@pcwizz) walks through what it takes to actually fuzz async Rust: the naive approaches that don't work, and an involved technique that does - involving LibAFL, user mode QEMU, and a fair amount of head scratching.
🔗 https://oxidizeconf.com/sessions/awaiting_exploitation
#Oxidize2026 #RustLang #Fuzzing #SecurityResearch #AsyncRust
-
Sometimes I’ve found myself banging my head against the keyboard trying to contact companies to help them fix their misconfigurations and exposed servers.
After several frustrating experiences, I decided to create my own clear and structured Responsible Disclosure methodology.
Today I’m sharing it with you 👇
This flow represents how I handle vulnerabilities — always prioritizing ethical contact, escalation when necessary, and only publishing write-ups once the issue is fixed.
Opinions and constructive feedback are more than welcome. Have you faced similar situations? What’s your approach?
-
Sometimes I’ve found myself banging my head against the keyboard trying to contact companies to help them fix their misconfigurations and exposed servers.
After several frustrating experiences, I decided to create my own clear and structured Responsible Disclosure methodology.
Today I’m sharing it with you 👇
This flow represents how I handle vulnerabilities — always prioritizing ethical contact, escalation when necessary, and only publishing write-ups once the issue is fixed.
Opinions and constructive feedback are more than welcome. Have you faced similar situations? What’s your approach?
-
https://winbuzzer.com/2026/05/19/anthropic-says-it-began-letting-mythos-users-share-xcxwbn/
Anthropic has loosened sharing limits for Claude Mythos after earlier confidentiality restrictions, turning a tightly controlled cyber program into a broader disclosure channel.
#AI #ClaudeMythos #Anthropic #Claude #ProjectGlasswing #AISecurity #Cybersecurity #ThreatIntelligence #SecurityResearch #AIModels #AISafety
-
https://winbuzzer.com/2026/05/16/windows-11-and-microsoft-edge-hacked-at-pwn2own-be-xcxwbn/
Microsoft Edge and Windows 11 were successfully exploited at the Pwn2Own Berlin 2026 hacking event, contributing to a $523,000 day-one payout total.
#Cybersecurity #MicrosoftEdge #Windows11 #Pwn2Own #SecurityResearch #Exploits #ZeroDayVulnerabilities #WebBrowsers #WindowsSecurity
-
https://winbuzzer.com/2026/05/14/openais-gpt-55-matches-claude-mythos-in-security-tests-xcxwbn/
A UK AI Security Institute evaluation put GPT-5.5 near Claude Mythos on vulnerability-finding tasks.
#AI #GPT55Cyber #ClaudeMythos #UKAISecurityInstitute #OpenAI #Anthropic #Claude #AIBenchmarks #SecurityResearch #Cybersecurity
-
https://winbuzzer.com/2026/05/14/microsoft-launches-mdash-after-finding-16-windows-flaws-xcxwbn/
Microsoft has launched the MDASH agentic security system beating OpenAI and Anthropic on the CyberGym benchmark.
#AI #Microsoft #Cybersecurity #MDASH #AgenticAI #AIAgents #Cybersecurity #SecurityResearch