Security
Vulnerabilities, exploits, hardening and security engineering.
74 links, newest first.
- SecurityArticle
Post claims iOS IPA decryption without a physical iPhone
The post links to a report about decrypting FairPlay-protected iOS IPAs, claiming the process works without a physical iPhone or jailbreak.
The claim may interest engineers studying iOS app protection and reverse engineering.
- SecurityPaper
How to Back Up High-Value Secret Keys
The post links to a paper about backing up high-value secret keys.
Secret-key backup is a security engineering concern for systems that depend on valuable keys.
- SecurityRepository
Practical cryptography course covers PIR and TLS
A practical cryptography course covering PIR in practice, TLS 1.3, post-quantum integration, and TLS attestation.
Engineers can use it to explore practical cryptography topics and TLS features.
- SecurityArticle
Signing TLS Handshakes Inside a TPM in Go
The article shows how to use a client certificate whose private key stays in a TPM, covering what Go's crypto/tls requires and the cost per handshake.
Useful for engineers evaluating TPM-backed client keys and their performance impact in Go TLS connections.
- SecurityArticle
Decrypt TLS 1.3 HTTPS traffic in Wireshark
The blog explains how to use SSLKEYLOGFILE to capture TLS key information and load it into Wireshark to inspect HTTP requests in captured HTTPS traffic.
Useful for engineers troubleshooting and analyzing HTTPS traffic they are authorized to inspect.
- SecurityPaper
Study reports code overlap between Geedge leak and Great Firewall
The post links to a USENIX Security paper whose authors report source-code overlap between leaked Geedge Networks code and China's Great Firewall, including DNS and RST injection behavior.
The reported overlap may help engineers understand how network filtering systems implement traffic injection.
- SecurityPaper
IO Factory simulates AI-enabled influence campaigns
The paper introduces IO Factory, an AI-driven framework for simulating information and influence campaigns as integrated, traceable processes. It describes coordinated AI agents that adapt to platform feedback and disguise campaigns as ordinary social interaction.
Security teams can use the work to study coordinated, adaptive influence campaigns that are difficult to detect from individual messages.
- SecurityPaper
ExploitGym evaluates AI agents’ ability to exploit vulnerabilities
ExploitGym studies whether AI agents can turn security vulnerabilities into concrete impacts such as unauthorized file access or code execution. The task requires low-level program reasoning, runtime adaptation, and sustained progress.
It offers a way to evaluate AI agents’ capabilities for converting vulnerabilities into real attacks.
- SecurityPost on X
How reverse-proxy phishing can capture MFA session cookies
The post describes phishing kits that proxy a victim’s login and MFA interaction with a real service, then intercept the resulting session cookie. It names Evilginx, Modlishka, and Muraena.
Engineers can use this attack pattern to inform phishing defenses and authentication design.
- SecurityRepository
obfus.h: Compile-time obfuscation for C
obfus.h is a macro header for compile-time C obfuscation on Windows x86/x64 using tcc. The post says it supports virtualization, anti-debugging, and control-flow obfuscation.
Engineers can assess its code-mutation techniques when evaluating software protection and reverse-engineering resistance.
- SecurityPaper
Practical Privacy and Availability Attacks on 4G/LTE
A 2015 paper by Altaf Shaik et al. examines practical attacks against privacy and availability in 4G/LTE mobile communication systems.
Relevant to engineers assessing privacy and availability risks in mobile networks.
- SecurityPost on X
Device-code phishing is not specific to Wi-Fi
The author argues that device-code authentication phishing can happen over Ethernet or the internet, not only over Wi-Fi.
It cautions engineers against treating device-code phishing as a Wi-Fi-specific risk.
- SecurityArticle
DeepSec Benchmark Compares Models for Vulnerability Discovery
The post reports private benchmark results for Kimi K3 and other models using DeepSec, an open-source harness for finding vulnerabilities in large codebases. It compares recall, precision, and cost on an undisclosed open-core application.
The results offer a cost-and-performance comparison for engineers evaluating models for security analysis.
- SecurityPost on X
uv can check packages against OSV before installation
Setting `UV_MALWARE_CHECK=1` makes uv cross-reference the OSV database before installing packages from a remote registry and block packages reported as malware.
This adds a malware check before package installation from remote registries.
- SecurityPost on X
Prompt injection in AI-assisted binary reverse engineering
The post describes Naval Postgraduate School research on embedding short prompt-injection strings in C binaries to influence LLM-powered reverse-engineering agents during Ghidra analysis. It says the researchers used an AutoDAN-style genetic algorithm to generate payloads that fit Ghidra’s…
Engineers using AI for binary analysis should consider that strings in analyzed binaries can act as untrusted instructions to the model.
- SecurityRepository
Anthropic’s Reference Harness for Security Scanning and Patching
The repository provides skills for threat modeling, scanning, triage, and patching, plus a customizable autonomous scanning harness.
Engineers can explore a reference workflow for security analysis and vulnerability remediation.
- SecurityArticle
QuadRF Uses Phased-Array Radio to Track Drones and Detect WiFi
Jeff Geerling describes QuadRF, a phased-array radio built around a Raspberry Pi 5 and FPGA board. It uses signal processing and beamforming to track drones and detect WiFi through walls.
Its sensing capabilities are relevant to engineers assessing wireless privacy and security.
- SecurityPaper
Intel refreshes paper on memory protections for confidential computing
Intel refreshed its “Intel Architecture Memory Protections for Confidential Computing” technical paper, document 869103.
The paper may help engineers understand Intel architecture memory protections used in confidential computing.
- SecurityArticle
Tradecraft Garden publishes evasion research and linker tooling
Tradecraft Garden shares evasion tradecraft openly. The post describes Crystal Palace, a linker with code transformation and randomization features, YARA rule generation, and support for reusable tradecraft modules.
The techniques may help red teams test capabilities and defenders evaluate detection coverage.
- SecurityRepository
Strix: Open-Source AI Penetration Testing Tool
Strix is an open-source AI penetration testing tool for finding and fixing application vulnerabilities.
Engineers can review the repository as a potential tool for application security testing.
Build with AgentLog
Send your own newsletter
CommsHarbor keeps contacts, consent and one-click unsubscribe together.
Free workspace
Open CommsHarbor




