Skip to content
EN

Security

Vulnerabilities, exploits, hardening and security engineering.

74 links, newest first.

Get the weekly briefing

The best new links of the topics you pick, summarized with the source. At most one email a week.

Topics: Security

Before the first issue we email you to confirm; leaving takes one click. Sent with CommsHarbor. Privacy

  1. SecurityRepository

    Veritensor announces version 1.4.0

    Veritensor v1.4.0 is described as a major release that expands the project from a model scanner into an AI security platform.

    Engineers evaluating AI security tools can review the release and its stated change in scope.

  2. SecurityArticle

    Sysdig details AWS intrusion from exposed S3 credentials to Bedrock

    Sysdig describes an AWS compromise that begins with exposed credentials in S3, pivots through Lambda, and escalates to Bedrock access. An Elastic rule detects external layers added to Lambda functions.

    The case and detection rule can help engineers investigate suspicious Lambda changes and cloud privilege escalation.

  3. SecurityArticle

    Using AI to turn threat reports into detection insights

    Microsoft describes an AI-assisted workflow that extracts TTPs from threat reports, maps them to existing detection coverage, and flags potential gaps. Human experts review and validate the results.

    The workflow could help security teams identify detection gaps and accelerate detection engineering.

  4. Study Evaluates Gradient Inversion Attacks in Federated Learning

    The study examines gradient inversion attacks in federated learning. It reports that the most practical attack method remains unreliable and outlines a three-stage defense approach.

    Engineers designing federated learning systems can use the findings to assess privacy risks and defenses.

  5. SecurityRepository

    Leaker: passive credential leak enumeration

    Leaker is a tool described as finding credential leaks for email addresses through passive online sources. Its GitHub page calls it a passive leak enumeration tool.

    Engineers can review the repository to assess a passive approach to checking for exposed credentials.

  6. SecurityPost on X

    Collection of Prompt Injection Vectors and Strategies

    The post points to a collection of prompt injection vectors and strategies, with examples.

    It may help engineers identify prompt injection techniques when assessing or hardening systems.

  7. SecurityRepository

    CyberBlue bundles blue-team security tools in containers

    CyberBlue is a containerized platform that brings together open-source tools for SIEM, DFIR, CTI, SOAR, and network analysis.

    Engineers can review how the platform combines tools used for security monitoring and incident response.

  8. SecurityRepository

    Search index for public CVE proof-of-concept exploits

    The GitHub project indexes public CVE proof-of-concept exploits from GitHub, Nuclei, ExploitDB, Metasploit, and Vulhub.

    Engineers can use the index to find public exploit examples relevant to vulnerability research and security testing.

  9. SecurityRepository

    DocEx emulates exfiltration of sensitive documents

    DocEx is an APT emulation tool for exfiltrating .docx, .pptx, .xlsx, and .pdf files.

    Security teams can use it to assess defenses against document exfiltration.

  10. SecurityArticle

    Chrome Browser Exploitation: V8 and JavaScript Internals

    A three-part series on Chrome browser internals and exploitation. Part 1 introduces V8 and JavaScript internals.

    Useful background for engineers studying browser security and exploitation.

  11. SecurityArticle

    Windows Defender Bypass Techniques: Direct Syscalls and XOR

    A two-part series on bypassing Windows Defender, covering antivirus behavior, lab setup, and evasion techniques using direct syscalls and XOR encryption. The first part provides basic code for experimentation.

    Understanding these evasion techniques can help security engineers assess antivirus defenses and build better detection.

  12. HPAC-IDS Uses Hierarchical Attention for Intrusion Detection

    HPAC-IDS segments raw network packets into fixed-size segments and processes them with hierarchical structures and self-attention. Experiments on CIC-IDS2017 report high accuracy, low false positive rates, and resilience to adversarial methods.

    The paper describes a packet-based intrusion detection approach and evaluates its accuracy, false positives, and adversarial resilience.

  13. SecurityRepository

    White-hat frontrunning script for compromised wallets

    An open-source Bash script aims to help recover funds from compromised wallets before sweeper bots move them. It uses Linux tools and Foundry’s cast and chisel.

    Security engineers can review the recovery approach and its dependencies for incident response involving compromised wallets.

  14. SecurityRepository

    Open-source utilities for circumventing deep packet inspection

    The post points to GoodbyeDPI, a Windows utility for deep packet inspection circumvention, and two other repositories: ByeDPIAndroid and zapret.

    Engineers working on network filtering and censorship circumvention can review these open-source tools.

Build with AgentLog

List your MCP, skill or plugin

Reach the engineers who read these briefings.

Sponsor AgentLog

Footer, sidebar or featured slot for 30 days.

From US$ 60

See the slots

Send your own newsletter

CommsHarbor keeps contacts, consent and one-click unsubscribe together.

Free workspace

Open CommsHarbor