Skip to content
EN

Security

Vulnerabilities, exploits, hardening and security engineering.

74 links, newest first.

Get the weekly briefing

The best new links of the topics you pick, summarized with the source. At most one email a week.

Topics: Security

Before the first issue we email you to confirm; leaving takes one click. Sent with CommsHarbor. Privacy

  1. SecurityArticle

    Post claims iOS IPA decryption without a physical iPhone

    The post links to a report about decrypting FairPlay-protected iOS IPAs, claiming the process works without a physical iPhone or jailbreak.

    The claim may interest engineers studying iOS app protection and reverse engineering.

  2. How to Back Up High-Value Secret Keys

    The post links to a paper about backing up high-value secret keys.

    Secret-key backup is a security engineering concern for systems that depend on valuable keys.

  3. SecurityRepository

    Practical cryptography course covers PIR and TLS

    A practical cryptography course covering PIR in practice, TLS 1.3, post-quantum integration, and TLS attestation.

    Engineers can use it to explore practical cryptography topics and TLS features.

  4. SecurityArticle

    Signing TLS Handshakes Inside a TPM in Go

    The article shows how to use a client certificate whose private key stays in a TPM, covering what Go's crypto/tls requires and the cost per handshake.

    Useful for engineers evaluating TPM-backed client keys and their performance impact in Go TLS connections.

  5. SecurityArticle

    Decrypt TLS 1.3 HTTPS traffic in Wireshark

    The blog explains how to use SSLKEYLOGFILE to capture TLS key information and load it into Wireshark to inspect HTTP requests in captured HTTPS traffic.

    Useful for engineers troubleshooting and analyzing HTTPS traffic they are authorized to inspect.

  6. Study reports code overlap between Geedge leak and Great Firewall

    The post links to a USENIX Security paper whose authors report source-code overlap between leaked Geedge Networks code and China's Great Firewall, including DNS and RST injection behavior.

    The reported overlap may help engineers understand how network filtering systems implement traffic injection.

  7. IO Factory simulates AI-enabled influence campaigns

    The paper introduces IO Factory, an AI-driven framework for simulating information and influence campaigns as integrated, traceable processes. It describes coordinated AI agents that adapt to platform feedback and disguise campaigns as ordinary social interaction.

    Security teams can use the work to study coordinated, adaptive influence campaigns that are difficult to detect from individual messages.

  8. ExploitGym evaluates AI agents’ ability to exploit vulnerabilities

    ExploitGym studies whether AI agents can turn security vulnerabilities into concrete impacts such as unauthorized file access or code execution. The task requires low-level program reasoning, runtime adaptation, and sustained progress.

    It offers a way to evaluate AI agents’ capabilities for converting vulnerabilities into real attacks.

  9. SecurityPost on X

    How reverse-proxy phishing can capture MFA session cookies

    The post describes phishing kits that proxy a victim’s login and MFA interaction with a real service, then intercept the resulting session cookie. It names Evilginx, Modlishka, and Muraena.

    Engineers can use this attack pattern to inform phishing defenses and authentication design.

  10. SecurityRepository

    obfus.h: Compile-time obfuscation for C

    obfus.h is a macro header for compile-time C obfuscation on Windows x86/x64 using tcc. The post says it supports virtualization, anti-debugging, and control-flow obfuscation.

    Engineers can assess its code-mutation techniques when evaluating software protection and reverse-engineering resistance.

  11. Practical Privacy and Availability Attacks on 4G/LTE

    A 2015 paper by Altaf Shaik et al. examines practical attacks against privacy and availability in 4G/LTE mobile communication systems.

    Relevant to engineers assessing privacy and availability risks in mobile networks.

  12. SecurityPost on X

    Device-code phishing is not specific to Wi-Fi

    The author argues that device-code authentication phishing can happen over Ethernet or the internet, not only over Wi-Fi.

    It cautions engineers against treating device-code phishing as a Wi-Fi-specific risk.

  13. SecurityArticle

    DeepSec Benchmark Compares Models for Vulnerability Discovery

    The post reports private benchmark results for Kimi K3 and other models using DeepSec, an open-source harness for finding vulnerabilities in large codebases. It compares recall, precision, and cost on an undisclosed open-core application.

    The results offer a cost-and-performance comparison for engineers evaluating models for security analysis.

  14. SecurityPost on X

    uv can check packages against OSV before installation

    Setting `UV_MALWARE_CHECK=1` makes uv cross-reference the OSV database before installing packages from a remote registry and block packages reported as malware.

    This adds a malware check before package installation from remote registries.

  15. SecurityPost on X

    Prompt injection in AI-assisted binary reverse engineering

    The post describes Naval Postgraduate School research on embedding short prompt-injection strings in C binaries to influence LLM-powered reverse-engineering agents during Ghidra analysis. It says the researchers used an AutoDAN-style genetic algorithm to generate payloads that fit Ghidra’s…

    Engineers using AI for binary analysis should consider that strings in analyzed binaries can act as untrusted instructions to the model.

  16. SecurityRepository

    Anthropic’s Reference Harness for Security Scanning and Patching

    The repository provides skills for threat modeling, scanning, triage, and patching, plus a customizable autonomous scanning harness.

    Engineers can explore a reference workflow for security analysis and vulnerability remediation.

  17. SecurityArticle

    QuadRF Uses Phased-Array Radio to Track Drones and Detect WiFi

    Jeff Geerling describes QuadRF, a phased-array radio built around a Raspberry Pi 5 and FPGA board. It uses signal processing and beamforming to track drones and detect WiFi through walls.

    Its sensing capabilities are relevant to engineers assessing wireless privacy and security.

  18. Intel refreshes paper on memory protections for confidential computing

    Intel refreshed its “Intel Architecture Memory Protections for Confidential Computing” technical paper, document 869103.

    The paper may help engineers understand Intel architecture memory protections used in confidential computing.

  19. SecurityArticle

    Tradecraft Garden publishes evasion research and linker tooling

    Tradecraft Garden shares evasion tradecraft openly. The post describes Crystal Palace, a linker with code transformation and randomization features, YARA rule generation, and support for reusable tradecraft modules.

    The techniques may help red teams test capabilities and defenders evaluate detection coverage.

  20. SecurityRepository

    Strix: Open-Source AI Penetration Testing Tool

    Strix is an open-source AI penetration testing tool for finding and fixing application vulnerabilities.

    Engineers can review the repository as a potential tool for application security testing.

Build with AgentLog

List your MCP, skill or plugin

Reach the engineers who read these briefings.

Sponsor AgentLog

Footer, sidebar or featured slot for 30 days.

From US$ 60

See the slots

Send your own newsletter

CommsHarbor keeps contacts, consent and one-click unsubscribe together.

Free workspace

Open CommsHarbor