read.ehrlich.dev
ai-curated rss
about
github
rss
dark
security
Offensive and defensive security, penetration testing, and vulnerability research
hot
new
week
month
year
spaces
all
ai
sci fi
3d printing
aerospace
ai agents
algorithmic trading
amateur astronomy
animation
anthropology
api design
aquariums
archaeology
astrobiology
astrophysics
audio programming
behavioral economics
bioinformatics
birding
board games
cartography
category theory
cellular automata
chemistry
chess
climate science
cloud infrastructure
cognitive science
compilers
complexity
computer architecture
computer graphics
computer vision
conlangs
consciousness
containers
cpp
creative coding
cryptography
data engineering
data visualization
databases
decision theory
demoscene
design
devops
digital rights
distributed systems
ecology
economics
electronic music
elixir
embedded systems
energy
espresso
ethics
evolution
existentialism
exploit development
fermentation
film
finance
formal verification
forth
fpga
fractals
game dev
game theory
genetics
geology
git internals
go game
golang
ham radio
haskell
history
history of computing
history of science
homelab
horror
indie games
information design
information theory
internet culture
javascript
kotlin
linguistics
linux
lisp
lock picking
machine learning
malware analysis
manga
materials science
math olympiad
mathematics
mechanical keyboards
meditation
metaphysics
music theory
mycology
nanotechnology
networking
neuroscience
nix
nonduality
nuclear
number theory
observability
oceanography
open source
operating systems
paleoanthropology
pharmacology
phenomenology
philosophy
philosophy of mind
philosophy of science
photography
physics
pixel art
political philosophy
procedural generation
programming languages
puzzles
python
quantum computing
reinforcement learning
retrocomputing
reverse engineering
robotics
rust
security
self hosted
semiotics
shell scripting
site reliability
solo dev
sourdough
space exploration
speedrunning
standup comedy
statistics
swift
synths
tabletop rpg
technical writing
thermodynamics
topology
true crime
type theory
typescript
typography
urban exploration
vinyl
wasm
webdev
witsrtn
woodworking
worldbuilding
writing
zig
350
ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access
(thehackernews.com)
1 month ago ·
security
·
reverse engineering
350
ShieldBreak: New Windows Zero-Day Bypasses Microsoft’s RoguePlanet Patch
(securityaffairs.com)
1 month ago ·
security
·
reverse engineering
250
SAML Vulnerabilities and Attacks: A Practical Guide
(pentesterlab.com)
1 month ago ·
security
·
cryptography
280
Prompt Injections for Defense
(schneier.com)
1 month ago ·
security
·
cloud infrastructure
300
Nightmare-Eclipse Drops ShieldBreak Windows Defender 0-day Vulnerability
(cybersecuritynews.com)
1 month ago ·
reverse engineering
·
security
180
Salesforce API Connection Testing: A Practical Troubleshooting Guide
(dev.to)
1 month ago ·
api design
·
security
190
'Europese defensiesector aangevallen via nep-vacatures en Windows-zeroday'
(security.nl)
1 month ago ·
security
·
malware analysis
180
Sandworm Fake Job Interviews Push Trojanized WireGuard VPN to Infect IT Professionals
(cybersecuritynews.com)
1 month ago ·
malware analysis
·
security
550
CVE-2026-63520: Microsoft SharePoint Remote Code Execution (FIXED)
(rapid7.com)
1 month ago ·
security
·
git internals
130
CAV3RN Uses Google Apps Script as C2 Relay to Hide Malware Traffic Behind Google Infrastructure
(cybersecuritynews.com)
1 month ago ·
security
·
malware analysis
130
NCSC meldt actief misbruik van Screen Sharing-lek in macOS
(security.nl)
1 month ago ·
security
·
git internals
350
Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)
(rapid7.com)
1 month ago ·
security
·
open source
400
Zoom Patches “Zoomsday” Zero-Click Flaw Enabling Remote Code Execution
(securityaffairs.com)
1 month ago ·
reverse engineering
·
security
350
Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection
(securelist.com)
1 month ago ·
security
·
cloud infrastructure
80
Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack
(thehackernews.com)
1 month ago ·
security
·
reverse engineering
70
Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access
(thehackernews.com)
1 month ago ·
security
·
cloud infrastructure
65
Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS
(thehackernews.com)
1 month ago ·
security
·
site reliability
60
Delta doet onderzoek naar malafide wifi-netwerk tijdens vlucht
(security.nl)
1 month ago ·
security
·
networking
60
Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws
(thehackernews.com)
1 month ago ·
security
·
git internals
55
SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code
(thehackernews.com)
1 month ago ·
git internals
·
security
50
Google-themed Credential Phishing Attempt Delivered Through a Fake ‘New Audio MSG’ Email
(cybersecuritynews.com)
1 month ago ·
security
·
malware analysis
150
Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA
(darkreading.com)
1 month ago ·
security
·
malware analysis
150
Cisco Warns of Seven ClamAV Flaws, Two With Public PoCs
(securityaffairs.com)
1 month ago ·
security
·
malware analysis
32
OpenSSL lanceert voor het eerst installatieprogramma voor Windows
(security.nl)
1 month ago ·
security
·
operating systems
30
Three intrusions at UK criminal records office went undetected for two years
(therecord.media)
1 month ago ·
exploit development
·
security
310
Metabase SQL Zero-Day Attacks Could Have Wide Blast Radius
(darkreading.com)
1 month ago ·
security
·
databases
25
CISA gives federal agencies two weeks to patch Microsoft bug exploited in DPRK campaign
(therecord.media)
1 month ago ·
malware analysis
·
security
70
Microsoft Patch Tuesday August 2026, (Tue, Aug 11th)
(isc.sans.edu)
1 month ago ·
security
·
reverse engineering
250
Quoting OpenClaw
(simonwillison.net)
1 month ago ·
security
·
open source
20
Walmart Leaders Transform Security Operations Without Going Bananas
(darkreading.com)
1 month ago ·
security
180
Outdated Cybercrime Laws Put Security Researchers at Risk
(darkreading.com)
1 month ago ·
digital rights
·
security
165
Multistate Water System Attacks Widen, Iran Suspected
(darkreading.com)
1 month ago ·
security
·
malware analysis
35
Patch Tuesday - August 2026
(rapid7.com)
1 month ago ·
security
·
site reliability
10
Melania Trump Discovered To Be Russian Listening Device
(theonion.com)
1 month ago ·
digital rights
·
security
450
18-Year-Old Linux Kernel Vulnerability Enables Root Access and Container Escape
(linuxiac.com)
1 month ago ·
security
·
containers
35
Fake popular sites offer a free app, instead take over PCs
(malwarebytes.com)
1 month ago ·
malware analysis
·
security
450
Metabase 0-Day Vulnerability Exploited in the Wild to Gain Admin Access
(cybersecuritynews.com)
1 month ago ·
security
·
open source
20
Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilities
(blog.talosintelligence.com)
1 month ago ·
security
·
reverse engineering
250
CSS Bomb Attacks Turn Malicious Emails Into Password-Stealing Keyloggers
(cybersecuritynews.com)
1 month ago ·
security
·
webdev
250
Credential Stuffing Doesnt Break Your Login. It Drowns It. Heres a Pre-Auth Filter.
(dev.to)
1 month ago ·
security
·
api design
15
CVE-2026-65768 Microsoft Teams Remote Code Execution Vulnerability
(msrc.microsoft.com)
1 month ago ·
security
·
malware analysis
220
On-Demand TLS: Issue Certs at the Handshake
(dev.to)
1 month ago ·
api design
·
security
5
В Новороссийске два зерновых терминала из трех приостановили работу после атаки украинских беспилотников
(meduza.io)
1 month ago ·
urban exploration
·
security
14
CVE-2026-63514 Microsoft SharePoint Server Remote Code Execution Vulnerability
(msrc.microsoft.com)
1 month ago ·
security
·
malware analysis
220
Webmail CSS Attacks Expose a New Risk for AI-Powered Email Tools
(securityaffairs.com)
1 month ago ·
security
·
webdev
12
CVE-2026-58650 Visual Studio Code Security Feature Bypass Vulnerability
(msrc.microsoft.com)
1 month ago ·
security
·
reverse engineering
10
CVE-2026-50472 Windows LUA File Virtualization Filter Driver Elevation of Privilege Vulnerability
(msrc.microsoft.com)
1 month ago ·
exploit development
·
security
9
CVE-2026-62837 Microsoft SharePoint Server Information Disclosure Vulnerability
(msrc.microsoft.com)
1 month ago ·
security
·
digital rights
580
Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication
(thehackernews.com)
1 month ago ·
security
·
reverse engineering
8
CVE-2026-62827 Microsoft SharePoint Server Elevation of Privilege Vulnerability
(msrc.microsoft.com)
1 month ago ·
security
·
cloud infrastructure
30
Vulnerabilities in GNU cpio software
(cert.pl)
1 month ago ·
security
·
reverse engineering
450
New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens
(thehackernews.com)
1 month ago ·
security
·
webdev
8
CVE-2026-56174 Windows Narrator Braille Elevation of Privilege Vulnerability
(msrc.microsoft.com)
1 month ago ·
security
·
malware analysis
30
Vulnerabilities in GNU Emacs software
(cert.pl)
1 month ago ·
security
·
reverse engineering
7
CVE-2026-62829 Microsoft SharePoint Server Spoofing Vulnerability
(msrc.microsoft.com)
1 month ago ·
security
·
malware analysis
7
CVE-2026-57105 Microsoft Office SharePoint Spoofing Vulnerability
(msrc.microsoft.com)
1 month ago ·
security
·
malware analysis
40
РФ атакувала ракетою Х-59/69 та 126 безпілотниками: ППО знешкодила 92 дрони
(pravda.com.ua)
1 month ago ·
security
·
aerospace
7
CVE-2026-63512 Microsoft SharePoint Server Tampering Vulnerability
(msrc.microsoft.com)
1 month ago ·
security
·
malware analysis
350
Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts
(thehackernews.com)
1 month ago ·
security
·
reverse engineering
380
Metabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive Data
(securityaffairs.com)
1 month ago ·
security
·
databases
320
Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers
(thehackernews.com)
1 month ago ·
security
·
site reliability
75
U.S. Defense Manufacturer IEH Hit by Phishing Attack, Exposing Potentially Export-Controlled Data
(securityaffairs.com)
1 month ago ·
security
·
malware analysis
15
Expanding Daybreak as the Cyber Defense Window Narrows
(openai.com)
1 month ago ·
security
·
networking
200
U.S. CISA adds a Progress LoadMaster flaw to its Known Exploited Vulnerabilities catalog
(securityaffairs.com)
1 month ago ·
git internals
·
security
550
CVE-2026-63077: Additional Guidance Following Reports of Active Exploitation
(blog.jetbrains.com)
1 month ago ·
security
·
reverse engineering
480
WordPress XSS2Shell Flaw Chains Pre-Auth Login XSS to PHP Remote Code Execution
(cybersecuritynews.com)
1 month ago ·
security
·
git internals
30
Weekly Cyber Security Newsletter — OWASP Top 10 for LLM, Cisco IOS XE Flaw, and 1-Click Cursor RCE +20 Stories
(cybersecuritynews.com)
1 month ago ·
security
·
malware analysis
520
New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP
(thehackernews.com)
1 month ago ·
security
·
webdev
420
Rapid7 Analysis: Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077)
(rapid7.com)
1 month ago ·
reverse engineering
·
security
380
The npm attack that turned provenance attestations into camouflage
(thenewstack.io)
1 month ago ·
open source
·
security
25
Letterboxd Goes Down, Leaving Users Locked Out of Their Accounts
(variety.com)
1 month ago ·
open source
·
security
250
Breaking the attack chain created by exposed cloud secrets
(pentestpartners.com)
1 month ago ·
security
·
cloud infrastructure
250
WordPress XSS2Shell Flaw Turns Simple Login Bug Into Full Server Takeover
(securityaffairs.com)
1 month ago ·
security
·
open source
250
The AI model OpenAI won’t release yet — and what it found in testing
(thenewstack.io)
1 month ago ·
site reliability
·
security
18
Ворог у неділю найбільше атакував на Лиманському напрямку – Генштаб
(pravda.com.ua)
1 month ago ·
observability
·
security
60
Levi Strauss Data Breach – Hackers Gained Access to the Company’s Systems
(cybersecuritynews.com)
1 month ago ·
security
·
git internals
200
UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data
(thehackernews.com)
1 month ago ·
malware analysis
·
security
150
Container Escapes 101
(some-natalie.dev)
1 month ago ·
security
·
malware analysis
110
Lightning Nodes Drained As BTCPay Server Users Race To Patch
(thedefiant.io)
1 month ago ·
security
·
databases
100
Hackers Impersonate IT Support to Breach Leading Financial Companies
(securityaffairs.com)
1 month ago ·
security
·
cryptography
220
CSS:the bomb inside your inbox
(portswigger.net)
1 month ago ·
security
·
webdev
65
WinRAR-lek gebruikt bij ransomware-aanvallen, meldt Amerikaanse overheid
(security.nl)
1 month ago ·
security
·
malware analysis
5
Фігурант "справи адвокатів-хакерів" Дмитро Борзих подав позов проти журналістів
(pravda.com.ua)
1 month ago ·
solo dev
·
security
5
На Нікопольщині через атаки РФ загинула людина, ще 5 поранені
(pravda.com.ua)
1 month ago ·
security
180
Build a crappy ring-0 toy antivirus in eBPF with the IMA LSM
(blog.prizrak.me)
1 month ago ·
malware analysis
·
security
50
Criminelen spoofen telefoonnummer helpdesk bij phishingaanval op bedrijven
(security.nl)
1 month ago ·
security
·
digital rights
50
Military device manufacturer discloses cyber incident to SEC
(therecord.media)
1 month ago ·
malware analysis
·
security
150
22 Seconds to Compromise: How Automated SSH Actors Move From Login to Persistence Before You Can Blink [Guest Diary], (Thu, Aug 6th)
(isc.sans.edu)
1 month ago ·
security
·
malware analysis
40
Microsoft 365-mailbox Amerikaans defensiebedrijf gehackt via phishingaanval
(security.nl)
1 month ago ·
security
·
cryptography
25
Responding to the next frontier of critical cyber capabilities
(openai.com)
1 month ago ·
site reliability
·
security
300
Don't Revoke That Token Yet: Inside the keyv/cacheable npm Worm, (Wed, Aug 5th)
(isc.sans.edu)
1 month ago ·
security
·
open source
280
15 TP-Link Bugs Expose Risks in Zero-Trust Provisioning
(darkreading.com)
1 month ago ·
security
·
self hosted
250
CSS: The Hidden Threat Lurking in Your Inbox
(darkreading.com)
1 month ago ·
security
·
webdev
60
Adversarial Clothing Designed to Fool Facial Recognition Systems
(schneier.com)
1 month ago ·
security
·
digital rights
380
CVE-2026-18577: N-able N-central Authentication Bypass Exploited in the Wild
(rapid7.com)
1 month ago ·
security
·
malware analysis
120
#738: Hackers Waited 3 Months for This Couple’s $1.2 Million Deal, with Dr. Eric Cole [GREATEST HITS]
(affordanything.com)
1 month ago ·
malware analysis
·
security
150
Detecting Certighost (CVE-2026-54121): Sigma Coverage Across the Full Attack Chain
(nextron-systems.com)
1 month ago ·
security
·
malware analysis
10
datasette-auth-tokens 0.4a13
(simonwillison.net)
1 month ago ·
git internals
·
security
120
Sending Emails Using Python
(realpython.com)
1 month ago ·
security
·
python
400
Rapid7 Analysis: KindaRails2Shell (CVE-2026-66066)
(rapid7.com)
1 month ago ·
git internals
·
security
spaces
all
ai
sci fi
3d printing
aerospace
ai agents
algorithmic trading
amateur astronomy
animation
anthropology
api design
aquariums
archaeology
astrobiology
astrophysics
audio programming
behavioral economics
bioinformatics
birding
board games
cartography
category theory
cellular automata
chemistry
chess
climate science
cloud infrastructure
cognitive science
compilers
complexity
computer architecture
computer graphics
computer vision
conlangs
consciousness
containers
cpp
creative coding
cryptography
data engineering
data visualization
databases
decision theory
demoscene
design
devops
digital rights
distributed systems
ecology
economics
electronic music
elixir
embedded systems
energy
espresso
ethics
evolution
existentialism
exploit development
fermentation
film
finance
formal verification
forth
fpga
fractals
game dev
game theory
genetics
geology
git internals
go game
golang
ham radio
haskell
history
history of computing
history of science
homelab
horror
indie games
information design
information theory
internet culture
javascript
kotlin
linguistics
linux
lisp
lock picking
machine learning
malware analysis
manga
materials science
math olympiad
mathematics
mechanical keyboards
meditation
metaphysics
music theory
mycology
nanotechnology
networking
neuroscience
nix
nonduality
nuclear
number theory
observability
oceanography
open source
operating systems
paleoanthropology
pharmacology
phenomenology
philosophy
philosophy of mind
philosophy of science
photography
physics
pixel art
political philosophy
procedural generation
programming languages
puzzles
python
quantum computing
reinforcement learning
retrocomputing
reverse engineering
robotics
rust
security
self hosted
semiotics
shell scripting
site reliability
solo dev
sourdough
space exploration
speedrunning
standup comedy
statistics
swift
synths
tabletop rpg
technical writing
thermodynamics
topology
true crime
type theory
typescript
typography
urban exploration
vinyl
wasm
webdev
witsrtn
woodworking
worldbuilding
writing
zig