Как строить сканирование активов в MaxPatrol VM. Ч.2 — Windows-активы
Добрый день, дорогие читатели! В прошлой статье мы разбирали, как импортировать из Active Directory список ПК в домене. Сегодня разберем, как проска…
Tech news from the best sources
Добрый день, дорогие читатели! В прошлой статье мы разбирали, как импортировать из Active Directory список ПК в домене. Сегодня разберем, как проска…
There is a day every month when Microsoft releases its security patches. The second Tuesday. The industry calls it Patch Tuesday. The day after, inf…
Добрый день, немногочисленные дамы и многочисленные господа узкого мира ИБ! Представляюсь по случаю написания первой статьи на Хабр! Меня зовут Арис…
Уже несколько лет в Positive Labs мы исследуем механизмы безопасности в SoC RK35xx от Rockchip. За это время нам и другим исследователям безопасност…
Your Secrets Need a VDP, Not Just a Bug Bounty Bug bounty programs are valuable -- until they replace disclosure policies. Learn how unreasonable Po…
Introduction The manager’s directive to prevent session cookie reuse across devices originates from a practical observation: authenticated session c…
Originally published on tamiz.pro . GhostLock, designated CVE-2023-32233, is a use-after-free (UAF) vulnerability discovered in the Linux kernel's N…
Originally published on CyberNetSec . Executive Summary On July 11, 2026, the Australian Cyber Security Centre (ACSC) released a critical alert deta…
OpenBSD Privilege Escalation, GitHub AI Agent Leaks, & CDN Supply Chain Risks Today's Highlights This week's top security news features a critic…
Linux LUKS Vulnerability, Android Developer Verification Threat, GitHub Secret Scanning Guide Today's Highlights This week's top security news featu…
Apple Hide My Email Vulnerability, GitHub Hardening Guide, and Advisory Database Trends Today's Highlights This week, we delve into a critical Apple…
Undisclosed 0-Days, OpenZL for Zero-Trust, and Reddit's Anti-Spam Architecture Today's Highlights This week's security highlights feature a critical…
AI Content Detection, Zig Low-Level Hardening, & Sub-1nm Chip Security Focus Today's Highlights This week's highlights include a practical tool…
Securing AI: Codex Operational Bugs, Claude Output Integrity, Copilot Context Today's Highlights This week's top security news highlights critical o…
FIFA Hack Authentication Flaw, Chrome Ad Blocker End, AI Supply Chain Security Today's Highlights Today's top security news covers a critical real-w…
PyPI Supply Chain, OWASP LLM Top 10, & eBPF Cloud-Native Security Today's Highlights Today's security highlights include a critical new maliciou…
AI Provenance Risks, Honda Key Fob Vuln, & Rust Miri FFI Safety Today's Highlights This week, we examine critical security insights across diver…
Arch Linux Supply Chain Malware, repo-slopscore & AI Model Security Concerns Today's Highlights This week highlights a significant supply chain…
AI Agent Security, Malware Evasion, & LLM Data Leakage Risks Today's Highlights Today's highlights cover crucial security challenges, from sophi…
AMD RCE Ignored, GitHub Boosts Secret Scanning with LLMs, AUR Supply Chain Attack Today's Highlights This week, a critical RCE vulnerability in AMD…
Так уж повелось, что в Positive Labs исследованиями одноплатных платформ чаще всего занимаюсь я. Задачи при этом бывают разными: где-то нужно включи…
Май 2026 года ознаменовался всплеском критических уязвимостей в корпоративных и потребительских технологиях. Подводим итоги месяца: три уязвимости в…
AI Code Security: Claude's rsync Bugs; Europe's GNSS Interference & GPS Anomalies Today's Highlights This week in security, a deep dive explores…
Introduction: The Breakdown of Trust The recent public disclosure of a zero-day vulnerability in Visual Studio Code (VS Code) by a security research…
Дмитрий Беляев, CISO, подкастер, человек, который устал читать красивые отчёты Я провёл подкаст с двумя людьми, которых в нашем цеху представлять не…
GHES Key Rotation, Bug Bounty Program Refocus, AI Agent Permission Fatigue Today's Highlights This week's top security news features critical action…
Supply Chain & AI Security: GlassWorm Takedown, Prompt Injection RCE, Ubuntu 24 Hardening Today's Highlights This week, we delve into the succes…
Zero-Day Exploits, GitHub Actions Supply Chain Attacks, and OTP Auth Flaws Today's Highlights This week's top security news features a critical zero…
"BadHost" was found in Starlette, a package with 325 million weekly downloads.
Nginx CVE-2026-9256, AI Prompt Injection Defenses, and Claude AI Data Leak Demo Today's Highlights Today's security highlights include a critical ne…