
Reject Malicious Image Polyglots Post-EXIF Strip, Before CDN Ingestion
Stripping EXIF data from uploads is not enough; attackers can hide malicious payloads within seemingly valid JPEGs.

Five shifts. Five minutes. No noise.
No spam. Unsubscribe anytime. Powered by Beehiiv.

The individual behind the GTA 6 gameplay leaks has apparently cashed out of a memecoin, leaving investors with losses just before the official trailer dropped.

Generative AI has eliminated the obvious errors in phishing, making attacks hyper-personalized and harder to detect. The old playbook is obsolete.

A new audit reveals widespread security gaps in AI model deployment, prompting the release of MCPGrade to assess risk.

Stripping EXIF data from uploads is not enough; attackers can hide malicious payloads within seemingly valid JPEGs.

An advanced threat actor is using the ViPNet update mechanism to deploy malware on Russian government networks.
Improvised navigation aids are being added to Russian drones to maintain targeting capability amid satellite communication disruptions.

A custom firmware solution leverages a hashing algorithm to store an enormous blocklist on minimal hardware, offering a glimpse into efficient network-level ad blocking.

Developer creates MyDigitSign, a client-side PDF signer, to address privacy concerns and paywalls in online tools.

Attackers forge PDF bank statements by overwriting 'Producer' metadata, bypassing manual and automated checks.

A simple experiment reveals Cloudflare's bot detection targets browser fingerprints, not just IP addresses.

Background retry queues can upload original, un-sanitized photo files, exposing user location data.

A misconfigured GitHub workflow allowed a malicious actor to inject a second AI agent via an npm package, leading to a supply chain attack.
Update now: 7-Zip addresses remote code execution vulnerability triggered by malicious archives.