Search results

  1. Depov

    69% of browsers in the world are under attack. We understand how surveillance works through the usual Chrome function

    The usual synchronization feature in Google Chrome can imperceptibly turn the browser into a surveillance tool. To do this, the attacker does not need malware or technical skills - it is enough to access someone else's phone for a few minutes and connect your own Google account to the browser...
  2. Depov

    How To Become Anonymous Online

  3. Depov

    vm2 sandbox escape: analysis of three critical CVSS 10.0 shoots in Node.js

    Business logic of attack: why break the vm2 sandbox vm2 - npm-package to run untrusted JavaScript in an isolated Node.js environment. According to Endor Labs, the library is gaining more than a million weekly downloads, although the mainstreamer marked the project back in 2023 as a deprecated...
  4. Depov

    Safety of NHI in AI-Agents: attack paths, SIEM-detection and reinterpretation

    On the audit of the cloud infrastructure of the fintech company in March of this year found a service account of the LLM agent with rights s3:* and iam:PassRole. The token was not rotated for 9 months, and the agent used two API calls: s3:GetObject on one tank and bedrock:InvokeModel. The...
  5. Depov

    Again, the “Confirm the Entrance” window? Microsoft Allows Directors to Disable It

    Microsoft gave companies the opportunity to remove unnecessary requests when logging into enterprise Windows applications. After installing the July update, administrators will be able to automatically allow a single login on controlled computers. The change came in Windows 11...
  6. Depov

    12 super-attacks in three months. The Internet industry is losing the war to cheap botnets

    A few years ago, the power of DDoS-atabs of 1 terabit per second was considered a rarity and a reason for individual reports - now, according to CURATOR, such attacks have become a routine practice of intruders. The DDoS protection provider summed up the results of the first half of 2026 and...
  7. Depov

    Every LINUX Command You Need In 15 Minutes

  8. Depov

    CVE-2026-20223 in Cisco Secure Workload: bypassing REST API authentication and testing methodology

    CVSS 10.0. Ten out of ten. One HTTP request to the internal REST API Cisco Secure Workload without an authorization token – and a remote attacker reads the configuration and changes microsegment policies with Site Admin’s approaches across tenants boundaries. Neither cookie, nor Bearer token...
  9. Depov

    Grok Build just had to say “OK.” AI-assist Elon Musk instead leaked to the cloud the entire repository

    The Grok* Build tool sent entire user designs to the cloud, including the full history of changes and secrets deleted a few months ago. After the announcement, the developers stopped downloading the data, and Elon Musk promised to erase all the previously collected data. The problem...
  10. Depov

    2 million tracks from YouTube Music and hundreds of thousands of podcasts. Hacker revealed the source code of the service Suno

    The internal device of one of the largest services for the generation of music was revealed not in court, but after the hack. The hacker’s files indicate that Suno massively collected songs, lyrics and podcasts from YouTube Music, Deeze, Genius and other platforms to train their models...
  11. Depov

    Harvested envelope, DLL substitution and proxy inside svchost.exe. Positive Technologies reveals attack through ViPNet MFTP

    The program for secure document management, which is used by Russian companies and government agencies, has become a tool for infiltrating their own networks - an attack was detected through the standard functionality of the ViPNet FFTP service. Specialists of the expert security...
  12. Depov

    Beginners Guide to Hacking

  13. Depov

    Elastasticsearch security check, or “I see your indices”

    Elasticsearch often turns out to be the “heart” of logging, search, and analytics. It involves events of applications, nginks, audit trail logs, trading, payment events, user actions, debug information and sometimes what should not have gotten there at all. That is why the outlet of...
  14. Depov

    OAuth vulnerability WeChat Mini-Programs: three account capture vectors through OBA mys configuration

    Dynamic analysis 44 273 WeChat and 2 721 Baidu Mini-Programs revealed 1 834 cases of implementation curve of OAuth-like authorization - 619 applications contained a combination of several holes simultaneously (Shi et al., "MiniCAT: Understanding and Detecting Outhe Access Control Threats in...
  15. Depov

    Hidden spy for 1.6 million users. Popular browser expansion secretly collected the history of visits

    A popular browser extension can for years preserve the reputation of a secure tool while there is already a ready-made tracking mechanism inside. Google and Microsoft have removed ModHeader from Chrome and Edge stores after detecting a hidden builder of visits in the official version of the...
  16. Depov

    The head of Microsoft advises not to trust neural networks. Yes, yes, thereby, on which his company earns billions

    CEOs of companies usually praise products that they create themselves, but the head of Microsoft suddenly warned the business to stay away from one feature of modern neural networks - the one on which his own company is built. Satya Nadella in a personal post on the social network X said that...
  17. Depov

    AI is flying into orbit. Intel showed a Starfire chip for American military satellites

    Intel announced a chip that will work not in the data center, but in Earth orbit - in conditions of constant temperature changes from -55 to 125 degrees Celsius and under the flow of space radiation. The new system on the crystal was called Starfire and was created by order of the US...
  18. Depov

    Scan ANY Network From Your Phone!

  19. Depov

    Attacks on agent AI pypalines: how public GitHub issue captures workflow organizations

    In 2025-2026, the class of attacks on AI-agents in GitHub Actions is described: the malicious comment in the pull request forced agents - Copilot, Gemini CLI, Claude Code - to drain secrets, including API keys and GITHUB_TOKEN, directly to the public logs workflow. Zero interaction from the...
  20. Depov

    Bad Epoll (CVE-2026-46242): Linux LPE vulnerability analysis - from the kernel patch to operation

    Six machine instructions. The six-instruction race window – and Jaeyoung Chung of the Seoul National University Computer Security Lab turns the unvited process into root with 99 out of 100 attempts. Exploit published on oss-sec, bugs are registered as CVE-2026-46242 (Bad Epoll) Use-after-free in...
Top Bottom