read.ehrlich.dev
ai-curated rss
about
github
rss
dark
security
Offensive and defensive security, penetration testing, and vulnerability research
hot
new
week
month
year
spaces
all
ai
sci fi
3d printing
aerospace
ai agents
algorithmic trading
amateur astronomy
animation
anthropology
api design
aquariums
archaeology
astrobiology
astrophysics
audio programming
behavioral economics
bioinformatics
birding
board games
cartography
category theory
cellular automata
chemistry
chess
climate science
cloud infrastructure
cognitive science
compilers
complexity
computer architecture
computer graphics
computer vision
conlangs
consciousness
containers
cpp
creative coding
cryptography
data engineering
data visualization
databases
decision theory
demoscene
design
devops
digital rights
distributed systems
ecology
economics
electronic music
elixir
embedded systems
energy
espresso
ethics
evolution
existentialism
exploit development
fermentation
film
finance
formal verification
forth
fpga
fractals
game dev
game theory
genetics
geology
git internals
go game
golang
ham radio
haskell
history
history of computing
history of science
homelab
horror
indie games
information design
information theory
internet culture
javascript
kotlin
linguistics
linux
lisp
lock picking
machine learning
malware analysis
manga
materials science
math olympiad
mathematics
mechanical keyboards
meditation
metaphysics
music theory
mycology
nanotechnology
networking
neuroscience
nix
nonduality
nuclear
number theory
observability
oceanography
open source
operating systems
paleoanthropology
pharmacology
phenomenology
philosophy
philosophy of mind
philosophy of science
photography
physics
pixel art
political philosophy
procedural generation
programming languages
puzzles
python
quantum computing
reinforcement learning
retrocomputing
reverse engineering
robotics
rust
security
self hosted
semiotics
shell scripting
site reliability
solo dev
sourdough
space exploration
speedrunning
standup comedy
statistics
swift
synths
tabletop rpg
technical writing
thermodynamics
topology
true crime
type theory
typescript
typography
urban exploration
vinyl
wasm
webdev
witsrtn
woodworking
worldbuilding
writing
zig
315
PolyShell flaw exposes Magento and Adobe Commerce to file upload attacks
(securityaffairs.com)
2 months ago ·
security
·
open source
110
Malicious Script Injection in Trivy Compromise Enables Credential Theft
(cybersecuritynews.com)
2 months ago ·
security
·
containers
265
Critical Langflow Flaw CVE-2026-33017 Triggers Attacks within 20 Hours of Disclosure
(thehackernews.com)
2 months ago ·
security
·
reverse engineering
72
Oracle Patches Critical CVE-2026-21992 Enabling Unauthenticated RCE in Identity Manager
(thehackernews.com)
2 months ago ·
security
·
git internals
115
Oracle Issues Urgent Security Update for Critical RCE Flaw in Identity Manager and Web Services Manager
(cybersecuritynews.com)
2 months ago ·
security
·
git internals
140
Patch Now: Oracle's Fusion Middleware Has Critical RCE Flaw
(darkreading.com)
2 months ago ·
security
·
cloud infrastructure
155
Magento PolyShell Flaw Enables Unauthenticated Uploads, RCE and Account Takeover
(thehackernews.com)
2 months ago ·
security
·
open source
72
7,500+ Magento sites defaced in global hacking campaign
(securityaffairs.com)
2 months ago ·
security
·
open source
32
CISA Flags Apple, Craft CMS, Laravel Bugs in KEV, Orders Patching by April 3, 2026
(thehackernews.com)
2 months ago ·
security
·
git internals
75
Negotiating with the Board: Translating Active Risk into Financial Exposure
(rapid7.com)
2 months ago ·
security
·
algorithmic trading
28
FBI, CISA Warn Russian Hackers Are Targeting High-Value Individuals Through Signal
(cybersecuritynews.com)
2 months ago ·
security
·
cryptography
72
CISA Warns of Cisco Secure Firewall Management Center 0-Day Exploited in Ransomware Attacks
(cybersecuritynews.com)
2 months ago ·
security
·
malware analysis
55
Interlock Ransomware Targets Cisco Enterprise Firewalls
(darkreading.com)
2 months ago ·
security
·
malware analysis
220
Interlock group exploiting the CISCO FMC flaw CVE-2026-20131 36 days before disclosure
(securityaffairs.com)
2 months ago ·
security
·
malware analysis
18
Iranian among two charged over alleged attempt to enter UK nuclear submarine base
(theguardian.com)
2 months ago ·
security
38
Congress Is Dropping the Ball with a Clean Extension of FISA
(eff.org)
2 months ago ·
digital rights
·
security
48
CVE-2026-31381, CVE-2026-31382: Gainsight Assist Information Disclosure and Cross-Site Scripting (FIXED)
(rapid7.com)
2 months ago ·
security
·
site reliability
52
Ransomware Actors Expand EDR Killer Tactics Beyond Vulnerable Drivers
(cybersecuritynews.com)
2 months ago ·
malware analysis
·
security
45
Windows 11 March Update Breaks Microsoft Teams and OneDrive Sign-Ins
(cybersecuritynews.com)
2 months ago ·
security
·
git internals
22
Metasploit Wrap-Up 03/20/2026
(rapid7.com)
2 months ago ·
security
·
reverse engineering
135
ThreatsDay Bulletin: FortiGate RaaS, Citrix Exploits, MCP Abuse, LiveChat Phish & More
(thehackernews.com)
2 months ago ·
security
·
cloud infrastructure
28
New Fake Zoom Meeting Invite Scam Spreads Malware on Windows PCs
(hackread.com)
2 months ago ·
malware analysis
·
security
110
Everyday tools, extraordinary crimes: the ransomware exfiltration playbook
(blog.talosintelligence.com)
2 months ago ·
malware analysis
·
security
310
Snowflake Cortex AI Escapes Sandbox and Executes Malware
(simonwillison.net)
2 months ago ·
malware analysis
·
security
120
More notes on the Brazilian SYN attacks
(boston.conman.org)
2 months ago ·
security
·
cloud infrastructure
28
GSocket Backdoor Delivered Through Bash Script, (Fri, Mar 20th)
(isc.sans.edu)
2 months ago ·
malware analysis
·
security
88
Cloudflare with Discourse: Setup Guide (WAF & Security Rules)
(linuxblog.io)
2 months ago ·
cloud infrastructure
·
security
70
Russian APT targets Ukraine via Zimbra XSS flaw CVE-2025-66376
(securityaffairs.com)
2 months ago ·
security
·
cloud infrastructure
18
CVE-2026-26118 Azure MCP Server Tools Elevation of Privilege Vulnerability
(msrc.microsoft.com)
2 months ago ·
security
·
cloud infrastructure
8
Окупанти атакували Запоріжжя – загинуло подружжя, ще шестеро поранені, з них двоє дітей
(pravda.com.ua)
2 months ago ·
digital rights
·
security
145
Micropatches released for Microsoft Access Remote Code Execution Vulnerability (CVE-2025-62552)
(blog.0patch.com)
2 months ago ·
security
·
git internals
75
Hacking a Robot Vacuum
(schneier.com)
2 months ago ·
security
·
cloud infrastructure
7
Украинские беспилотники атаковали Уфу. Пострадали два человека
(meduza.io)
2 months ago ·
security
·
urban exploration
68
Sweden Breach Shows the Security Risks of National Digital ID Systems
(reclaimthenet.org)
2 months ago ·
security
·
digital rights
8
На Харківщині через російський обстріл є постраждалі, знеструмлені та пошкоджені будинки
(pravda.com.ua)
2 months ago ·
urban exploration
·
security
70
How One-Time Passwords work
(dkrichards.com)
2 months ago ·
cryptography
·
security
28
Speagle Malware Hijacks Cobra DocGuard to Steal Data via Compromised Servers
(thehackernews.com)
2 months ago ·
malware analysis
·
security
72
Interesting Message Stored in Cowrie Logs, (Wed, Mar 18th)
(isc.sans.edu)
2 months ago ·
security
·
malware analysis
25
You have to invite them in
(blog.talosintelligence.com)
2 months ago ·
security
·
cryptography
8
РФ атакувала дроном евакуаційний екіпаж на Донеччині: двоє загиблих, троє постраждалих
(pravda.com.ua)
2 months ago ·
security
·
digital rights
22
U.S. CISA adds a flaw in Cisco FMC and Cisco SCC Firewall Management to its Known Exploited Vulnerabilities catalog
(securityaffairs.com)
2 months ago ·
security
·
git internals
8
"Это метод в российском стиле" - The Guardian
(meduza.io)
2 months ago ·
true crime
·
security
68
Scans for "adminer", (Wed, Mar 18th)
(isc.sans.edu)
2 months ago ·
security
·
malware analysis
42
The Attack Cycle is Accelerating: Announcing the Rapid7 2026 Global Threat Landscape Report
(rapid7.com)
2 months ago ·
site reliability
·
security
580
Broken By Design: A Longitudinal Analysis of Cryptographic Failures in Alipay Mobile Payment Infrastructure
(eprint.iacr.org)
2 months ago ·
cryptography
·
security
82
How searching for a VPN could mean handing over your work login details
(malwarebytes.com)
2 months ago ·
security
·
malware analysis
65
IPv4 Mapped IPv6 Addresses, (Tue, Mar 17th)
(isc.sans.edu)
2 months ago ·
networking
·
security
65
Rapid7 Guidance on Observed Microsoft Teams Phishing Campaigns
(rapid7.com)
2 months ago ·
security
·
devops
68
/proxy/ URL scans with IP addresses, (Mon, Mar 16th)
(isc.sans.edu)
2 months ago ·
security
·
malware analysis
24
Lazarus, AI, and Trust Abuse: Top Enterprise Cybersecurity Risks 2026
2 months ago ·
distributed systems
·
security
38
Vulnerabilities in Raytha software
(cert.pl)
2 months ago ·
security
·
reverse engineering
560
A set of AppArmor vulnerabilities
(lwn.net)
2 months ago ·
reverse engineering
·
security
45
An Idea for Bypassing Linux Age Verification
(gavinhoward.com)
2 months ago ·
security
·
digital rights
25
Payload Ransomware claims the hack of Royal Bahrain Hospital
(securityaffairs.com)
2 months ago ·
security
·
malware analysis
42
Microsoft Releases Out-of-Band Patch For Critical RRAS RCE Vulnerabilities in Windows 11
(cybersecuritynews.com)
2 months ago ·
security
·
site reliability
22
Cert Authorities Check for DNSSEC From Today
(grepular.com)
2 months ago ·
security
·
cryptography
310
Nine CrackArmor Flaws in Linux AppArmor Enable Root Escalation, Bypass Container Isolation
(thehackernews.com)
2 months ago ·
security
65
Reducing email spam with a domain and catch-all aliases
(swiftrocks.com)
2 months ago ·
security
95
Critical LangSmith Account Takeover Vulnerability Puts Users at Risk
(cybersecuritynews.com)
2 months ago ·
security
48
Storm-2561 lures victims to spoofed VPN sites to harvest corporate logins
(securityaffairs.com)
2 months ago ·
security
·
cloud infrastructure
8
На Харківщині через атаки РФ загинула жінка, постраждали поліцейські й охоронець
(pravda.com.ua)
2 months ago ·
true crime
·
security
128
DRILLAPP: new backdoor targeting Ukrainian entities with possible links to Laundry Bear
(lab52.io)
2 months ago ·
security
·
digital rights
105
SQL Injection Vulnerability in Ally WordPress Plugin Exposes 200K+ Sites
(hackread.com)
2 months ago ·
security
95
Storm-2561 Spreads Trojan VPN Clients via SEO Poisoning to Steal Credentials
(thehackernews.com)
2 months ago ·
security
·
malware analysis
58
‘CrackArmor’ Vulnerability in AppArmor Impacts 12.6M Linux Systems
(hackread.com)
2 months ago ·
security
5
Росіяни атакували Дніпропетровщину: є загибла і 5 поранених
(pravda.com.ua)
2 months ago ·
security
·
game dev
20
Starbucks data breach impacts 889 employees
(securityaffairs.com)
2 months ago ·
data engineering
·
security
22
Воїни ГУР вдарили по двох російських військових суднах
(pravda.com.ua)
2 months ago ·
security
15
Росіяни атакували цивільну інфраструктуру Сумщини: 3 постраждалих
(pravda.com.ua)
2 months ago ·
security
·
urban exploration
20
‘I won’t hide it, I’m scared’: drone strike alerts Cyprus to its inadequate bomb shelters
(theguardian.com)
2 months ago ·
cloud infrastructure
·
security
240
This Android vulnerability can break your lock screen in under 60 seconds
(malwarebytes.com)
2 months ago ·
security
·
malware analysis
18
У Греції заявили про атаку на танкер під їхнім прапором біля Новоросійська
(pravda.com.ua)
2 months ago ·
security
·
oceanography
32
Metasploit Wrap-Up 03/13/2026
(rapid7.com)
2 months ago ·
security
·
containers
52
Watch out for fake Malwarebytes renewal notices in your calendar
(malwarebytes.com)
2 months ago ·
malware analysis
·
security
18
В Амстердамі стався вибух біля єврейської школи
(pravda.com.ua)
2 months ago ·
security
·
digital rights
70
Mind the gravity
(scadastrangelove.blogspot.com)
2 months ago ·
site reliability
·
security
24
Chromium: CVE-2026-3942 Incorrect security UI in PictureInPicture
(msrc.microsoft.com)
2 months ago ·
security
·
malware analysis
45
US Agencies Face CISA Deadline Over Critical Cisco SD-WAN Flaw
(hackread.com)
2 months ago ·
security
10
Собянин сообщил о массовой атаке дронов на Москву. Сбиты более 30 беспилотников
(meduza.io)
2 months ago ·
urban exploration
·
security
130
Critical SQL Injection bug in Ally plugin threatens 400,000+ WordPress sites
(securityaffairs.com)
2 months ago ·
security
8
Росіяни вдарили по житловому кварталу Запоріжжя: одна людина загинула, 10 поранені
(pravda.com.ua)
2 months ago ·
security
·
game dev
28
Most Google Cloud Attacks Start With Bug Exploitation
(darkreading.com)
2 months ago ·
cloud infrastructure
·
security
24
CVE-2026-25172 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
(msrc.microsoft.com)
2 months ago ·
security
·
site reliability
22
CVE-2026-25173 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
(msrc.microsoft.com)
2 months ago ·
security
·
site reliability
22
Loblaw Data Breach – Hackers Accessed IT Network and Customer Information
(cybersecuritynews.com)
2 months ago ·
security
18
CVE-2026-26111 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
(msrc.microsoft.com)
2 months ago ·
security
·
site reliability
315
Six mistakes in ERC-4337 smart accounts
(blog.trailofbits.com)
2 months ago ·
cryptography
·
security
68
Microsoft Authenticator could leak login codes—update your app now
(malwarebytes.com)
2 months ago ·
security
·
reverse engineering
38
A.B. 1043’s Internet Age Gates Hurt Everyone
(eff.org)
2 months ago ·
digital rights
·
security
42
Hackers Use Cloudflare Human Check to Hide Microsoft 365 Phishing Pages
(hackread.com)
2 months ago ·
security
5
У трьох областях є загиблий та 15 поранених цивільних
(pravda.com.ua)
2 months ago ·
game dev
·
security
28
Hackers Are Compromising Signal Accounts. Don’t Be Next.
(reclaimthenet.org)
2 months ago ·
security
·
malware analysis
380
FortiGate Edge Intrusions | Stolen Service Accounts Lead to Rogue Workstations and Deep AD Compromise
(sentinelone.com)
2 months ago ·
cloud infrastructure
·
security
48
DirectX, OpenFOAM, Libbiosig vulnerabilities
(blog.talosintelligence.com)
2 months ago ·
security
70
Understanding GRC: How to Navigate Risks and Compliance Standards
(blackhillsinfosec.com)
2 months ago ·
digital rights
·
security
15
The Face of Penetration Testing is Changing: Announcing Metasploit Pro 5.0.0
(rapid7.com)
2 months ago ·
security
·
site reliability
28
Announcing Cloudflare Account Abuse Protection: prevent fraudulent attacks from bots and humans
(blog.cloudflare.com)
2 months ago ·
digital rights
·
security
38
Protect What Matters Most: Aligning Sensitive Data with Exposure Risk
(rapid7.com)
2 months ago ·
security
165
OAuth Device Code Phishing: A New Microsoft 365 Account Breach Vector
2 months ago ·
security
68
Six-Day and IP Address Certificates Available in Certbot
(letsencrypt.org)
2 months ago ·
cryptography
·
security
spaces
all
ai
sci fi
3d printing
aerospace
ai agents
algorithmic trading
amateur astronomy
animation
anthropology
api design
aquariums
archaeology
astrobiology
astrophysics
audio programming
behavioral economics
bioinformatics
birding
board games
cartography
category theory
cellular automata
chemistry
chess
climate science
cloud infrastructure
cognitive science
compilers
complexity
computer architecture
computer graphics
computer vision
conlangs
consciousness
containers
cpp
creative coding
cryptography
data engineering
data visualization
databases
decision theory
demoscene
design
devops
digital rights
distributed systems
ecology
economics
electronic music
elixir
embedded systems
energy
espresso
ethics
evolution
existentialism
exploit development
fermentation
film
finance
formal verification
forth
fpga
fractals
game dev
game theory
genetics
geology
git internals
go game
golang
ham radio
haskell
history
history of computing
history of science
homelab
horror
indie games
information design
information theory
internet culture
javascript
kotlin
linguistics
linux
lisp
lock picking
machine learning
malware analysis
manga
materials science
math olympiad
mathematics
mechanical keyboards
meditation
metaphysics
music theory
mycology
nanotechnology
networking
neuroscience
nix
nonduality
nuclear
number theory
observability
oceanography
open source
operating systems
paleoanthropology
pharmacology
phenomenology
philosophy
philosophy of mind
philosophy of science
photography
physics
pixel art
political philosophy
procedural generation
programming languages
puzzles
python
quantum computing
reinforcement learning
retrocomputing
reverse engineering
robotics
rust
security
self hosted
semiotics
shell scripting
site reliability
solo dev
sourdough
space exploration
speedrunning
standup comedy
statistics
swift
synths
tabletop rpg
technical writing
thermodynamics
topology
true crime
type theory
typescript
typography
urban exploration
vinyl
wasm
webdev
witsrtn
woodworking
worldbuilding
writing
zig