Denard.me
  • Blog
  • Dashboard
    • Dashboard
    • - Security Experts
    • - Security Operations
    • - Application Security
    • - Sysadmin
    • - Tech News
  • Services
  • Archives
  • Résumé
  • Contact

Security Experts

Anthony Ferrara

  • Wiring a Home Network
  • A PHP Compiler, aka The FFI Rabbit Hole
  • Protecting Against XSS In RAILS - JavaScript Contexts
  • Disclosure: WordPress WPDB SQL Injection - Technical
  • Disclosure: WordPress WPDB SQL Injection - Background
  • Ponderings on Odoriferous Syntactical Constructifications
  • Building an 8-bit Computer
  • Trust
  • All About Middleware
  • Simple, Easy, Risk and Change

Chris Hoff

  • On building fire extinguishers and fighting fires…
  • The 3 Immutable Rules Of Presentations…
  • Looking Forward to Catching Up At RSA…
  • Attribution is the new black…what’s in a name, anyway?
  • The Active Response Continuum & The Right To Cyber Self Defense…
  • Incomplete Thought: The Time Is Now For OCP-like White Box Security Appliances
  • J-Law Nudie Pics, Jeremiah, Privacy and Dropbox – An Epic FAIL of Mutual Distraction
  • How To Be a Cloud Mogul(l) – Our 2014 RSA “Dueling Banjos/Cloud/DevOps” Talk
  • On the Topic Of ‘Stopping’ DDoS.
  • The Easiest $20 I ever saved…

Elliptic News

  • Celebrating 40 years of Elliptic Curves in Cryptography (ECC), August 11, 2025
  • 25th Workshop on Elliptic Curve Cryptography, Taipei, Taiwan, Oct 30 – Nov 1, 2024
  • New cryptanalysis of M-SIDH isogeny cryptography
  • SIAM Conference on Applied Algebraic Geometry (AG23)
  • Some comments on the CSIDH group action
  • Equivalence between CDH and DLP
  • EdDSA standardized
  • Attacks on SIDH/SIKE
  • Breaking supersingular isogeny Diffie-Hellman (SIDH)
  • Hertzbleed Attack

Fillipio

  • Production ML-DSA Verification in 350 Lines of Python
  • Opaque, Interoperable Passkey Records (and a Go API)
  • Vulnerability Reports Are Not Special Anymore
  • Quantum Computers Are Not a Threat to 128-bit Symmetric Keys
  • A Cryptography Engineer’s Perspective on Quantum Computing Timelines
  • Turn Dependabot Off
  • Inspecting the Source of Go Modules
  • go.sum Is Not a Lockfile
  • Building a Transparent Keyserver
  • The 2025 Go Cryptography State of the Union

Graham Cluley

  • Shai-Hulud hackers: two men charged over TeamPCP’s global supply chain crime spree that hit OpenAI, …
  • US Navy tells sailors and their families: scrub your social media, enemies are watching
  • Smashing Security podcast #482: This hacker leaked GTA 6 – and launched their own cryptocurrency
  • Malicious Firefox add-ons caught stealing cryptowallet seed phrases and browser credentials
  • Gunra ransomware: what you need to know
  • Smashing Security podcast #481: Never say this to a robot dog
  • Prison for data analyst who tried to extort $2.5 million from his employer
  • An “invisible” car? Researcher uses machine learning to hide vehicles from Flock cameras
  • Smashing Security podcast #480: This is the AI service you should never sign up to
  • Meta’s Ray-Bans are being banned from pubs, restaurants, and theatres

Ivan Ristic

  • Bulletproof TLS and PKI, Second Edition is out
  • OpenSSL Cookbook 3rd Edition now available
  • Second edition of Bulletproof SSL and TLS now in preview
  • Announcing Bulletproof SSL and TLS, the 2017 revision
  • Bulletproof SSL and TLS, three years later
  • SSL Labs Grading Redesign (Preview 1)
  • SSL Labs Distrusts WoSign and StartCom certificates
  • CAA Mandated by CA/Browser Forum
  • Ticketbleed detection added to SSL Labs
  • What’s new in SSL Labs 1.26.5

Krebs on Security

  • Two Alleged ‘TeamPCP’ Hackers Arrested in Australia
  • Who’s Tracking You? Use This New Service to Find Out
  • Microsoft Plugs Nearly 400 Security Holes
  • Canadian Man Pleads Guilty in Snowflake Extortions
  • Read This Before You Buy That TV Streaming Stick
  • LG to Ban Residential Proxies from Smart TV Apps
  • Microsoft Patches a Record 570 Security Flaws
  • Lessons Learned from CISA’s Recent GitHub Leak
  • Felons, Fraudsters Flog Offensive Cybersecurity Startup
  • FBI Seizes NetNut Proxy Platform, Popa Botnet

Lenny Zeltser

  • The Security Autonomy Matrix: Deciding AI Authority
  • Five Questions to Answer Before Buying an AI Security Product
  • A Field Guide to the AI Security Market
  • Cyber Company Profiles: Independent Analysis of Security Vendors
  • What 239 Products Reveal About the Shape of AI Security
  • Benchmark Your AI Security Decisions: A Five-Minute Survey
  • A Report Template for Malware Analysis
  • Templates for Cybersecurity Executive Briefings
  • Handling High-Profile Vulnerabilities
  • Securing API Keys on Your Workstation

The MPC Lounge

  • 5th Bar-Ilan Winter School 2015: Advances in Practical Multiparty Computation
  • Publicly Auditable Secure Multiparty Computation
  • Faster Maliciously Secure Two-Party Computation Using the GPU
  • Adapt, adapt, adapt
  • MiniTrix for MiniMacs
  • Categorizing MPC
  • Communication-Efficient MPC for General Adversary Structures
  • Fair enough
  • How to use bitcoin to design fair protocols
  • Round-efficient black-box constructions of composable multi-party computation

Root Labs rdist

  • Rebooting
  • In Which You Get a Chance to Save Democracy
  • Was the past better than now?
  • Thought experiment on protocols and noise
  • Timing-safe memcmp and API parity
  • In Defense of JavaScript Crypto

Russ McRee

  • Moving blog to HolisticInfoSec.io
  • toolsmith #133 - Anomaly Detection & Threat Hunting with Anomalize
  • toolsmith #132 - The HELK vs APTSimulator - Part 2
  • toolsmith #131 - The HELK vs APTSimulator - Part 1
  • toolsmith #130 - OSINT with Buscador
  • toolsmith #129 - DFIR Redefined: Deeper Functionality for Investigators with R - Part 2
  • McRee added to ISSA's Honor Roll for Lifetime Achievement
  • toolsmith #128 - DFIR Redefined: Deeper Functionality for Investigators with R - Part 1
  • Toolsmith Tidbit: Windows Auditing with WINspect
  • Toolsmith Release Advisory: Magic Unicorn v2.8

Schneier on Security

  • Friday Squid Blogging: Truckload of Squid Spills in Rhode Island
  • AI Doesn’t Mean the End of Mathematics—at Least Not Yet
  • LLM-Based Social Engineering Scams
  • Spyware for Babies
  • Black Hat State of Security Vendors
  • Criminal Deception in Silicon Valley
  • Friday Squid Blogging: Neon Flying Squid
  • AI Is Learning to Write Genetic Code
  • More Incidents of AIs Going Rogue in Cybersecurity Challenges
  • Detailed Timeline of OpenAI’s Cyberattack on Hugging Face

Shtetl-Optimized

  • Anthropic’s LLM watermarking
  • Better than gold
  • Michael Rabin memorial conference
  • Enough with all the world-historic milestones
  • NISQ and quantum supremacy did not fail
  • Held Prize call for nominations (+ call for postdocs)
  • Announcing BQP Partners: my and my brother’s new angel-investing venture
  • Happy 250th!
  • An American privacy emergency: Guest post from Cynthia Dwork et al.
  • Spreading the Gospel of Theoretical Computer Science to an Omega(1) Fraction of Humanity: My Trevisan …

Troy Hunt

  • A Cautionary Tale About Data Breach Claims, Verification and Carhartt
  • Weekly Update 518: IoT Doorlock Nirvana with UniFi
  • Welcoming the Sri Lankan Government to Have I Been Pwned
  • Weekly Update 517: Cyber Ransoms
  • Weekly Update 516: Live From Vietnam
  • Welcoming the Nepalese Government to Have I Been Pwned
  • Weekly Update 515: Seeking Caffeine Utopia
  • Weekly Update 514: This Week in Data Breaches
  • Weekly Update 513: Clauding The Home Network
  • Weekly Update 512: IoT Lockout Fail

Xavier Mertens

  • Hack.lu 2023 Wrap-Up
  • [SANS ISC] macOS: Who’s Behind This Network Connection?
  • [SANS ISC] Python Malware Using Postgresql for C2 Communications
  • [SANS ISC] More Exotic Excel Files Dropping AgentTesla
  • [SANS ISC] Have You Ever Heard of the Fernet Encryption Algorithm?
  • [SANS ISC] Quick Malware Triage With Inotify Tools
  • [SANS ISC] From a Zalando Phishing to a RAT
  • [SANS ISC] Show me All Your Windows!
  • [SANS ISC] Are Leaked Credentials Dumps Used by Attackers?
  • [SANS ISC] Do Attackers Pay More Attention to IPv6?

Sec Ops

Checkpoint

  • Check Point Blocks Large-Scale Debt-Relief Email Phishing Campaign Targeting More Than 9,000 Organizations
  • The Approved-App Blind Spot: When Sanctioned AI Becomes Shadow AI
  • Back-to-School Cyber Risks Surge as Education Remains the World’s Most Attacked Sector
  • The Mistake That Exposed a Global Cyber Crime Operation
  • Reading the Signals in the OWASP LLM Top 10 2026
  • Ransomware Didn’t Slow Down in Q2 2026. It Just Spread Out.
  • July 2026 Cyber Threats Surge: Ransomware Attacks Double Year over Year as GenAI Data Exposure …
  • State Sponsored Hackers Use Fake Job Offers to Deliver New Zero Day Exploit
  • Native AI Security Comes to Claude: Why Anthropic’s Inference Hooks Matter
  • The Top Exposure Management Questions Security Leaders Ask (Part 1)

Cloudflare

  • BotBase for Operators: A clearer path to joining Cloudflare's directory of bots and agents
  • How we saved 100 terabytes of memory by optimizing 1.1.1.1’s DNS cache
  • The Cloudflare Blog – Brought to you by EmDash
  • Say it once: introducing Bot Preference Sync
  • From all-or-nothing to task-based OAuth consent
  • A revisit of remote Spectre attacks on Cloudflare Workers
  • BGP Role model: tracking the adoption of RFC 9234
  • How Cloudflare detects MCP traffic and helps secure it
  • Secure all your internal vibe-coded applications — in one click
  • Total eclipse of the Internet: traffic impacts in Iceland, Spain, and Portugal

Google Online Security Blog

  • AI threats in the wild: The current state of prompt injections on the web
  • Bringing Rust to the Pixel Baseband
  • Protecting Cookies with Device Bound Session Credentials
  • Google Workspace’s continuous approach to mitigating indirect prompt injections
  • VRP 2025 Year in Review
  • Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android
  • Cultivating a robust and efficient quantum-safe HTTPS
  • Staying One Step Ahead: Strengthening Android’s Lead in Scam Protection
  • Keeping Google Play & Android app ecosystems safe in 2025
  • New Android Theft Protection Feature Updates: Smarter, Stronger

Have I Been Owned

  • Carhartt - 12,933,413 breached accounts
  • NIUS - 6,090 breached accounts
  • Golf Canada - 568,972 breached accounts
  • Oz Hair and Beauty - 1,988,331 breached accounts
  • Fanlore - 144,520 breached accounts
  • RingCentral - 1,596,490 breached accounts
  • Alcon - 218,395 breached accounts
  • Brinks Home - 732,162 breached accounts
  • Exact Sciences - 10,869,543 breached accounts
  • Inter-Con Security - 276,114 breached accounts

Kaspersky

  • Detection blind spots: non-standard file formats in malicious email campaigns | Kaspersky official blog
  • What to do if you find someone else’s bank card | Kaspersky official blog
  • How to spot scam websites that your browser says are safe | Kaspersky official blog
  • Malware in car infotainment systems: how infection occurs | Kaspersky official blog
  • How to protect yourself from webcam spying: five simple steps | Kaspersky official blog
  • ClickFix on Steam forums: how malicious PowerShell commands install a crypto miner | Kaspersky official …
  • How to tell an AI-written book from an expert’s | Kaspersky official blog
  • What we know about the cryptocurrency theft through Adform ads | Kaspersky official blog
  • Detection blind spots: polyglot file formats in mass mailings and targeted attacks
  • Dangerous email attachments: the files you should never open | Kaspersky official blog

Search Security

  • What is incident response? A complete guide
  • 5 steps to approach BYOD compliance policies
  • What is identity and access management? Guide to IAM
  • Cybersecurity awareness quiz: Questions and answers
  • What is data masking?
  • What is antivirus software?
  • Top 15 IT security frameworks and standards explained
  • What is a stealth virus and how does it work?
  • What is Triple DES and why is it disallowed?
  • What is information security (infosec)?

Shodan

  • 5 Free Things for Everybody
  • Deep Dive: Malware Hunter
  • Deep Dive: http.favicon
  • Changelog: www.shodan.io
  • Developer Access to Shodan Trends
  • Accepting Crypto: A Vendor Perspective
  • Historical IP Information
  • nrich: A Tool for Fast IP enrichment
  • Introducing Data Feeds for Search Results
  • Introducing the InternetDB API

Tenable

  • Why a cryptographic inventory is key for addressing the quantum computing threat
  • How to build an exposure management program the business trusts: Lessons from Tenable’s CSO
  • Edge infrastructure under siege: what two independent datasets reveal about who's exploiting your perimeter
  • Frequently asked questions about the active threat to Siemens S7 Series PLCs
  • Oracle August 2026 Critical Security Patch Update Addresses 925 CVEs
  • Detecting cloud ransomware in Azure with Tenable One’s cloud detection and response capabilities
  • The Agentic AI threat cluster: Seven incidents, three actors, and what they mean for your …
  • Microsoft's August 2026 Patch Tuesday addresses 398 CVEs (CVE-2026-68820)
  • Agentic AI for cyber defenders: What security teams built at Black Hat USA 2026
  • AI code security with Claude Mythos Preview: Inside Tenable’s 500+ hours of testing for Project …

Threatpost

  • Student Loan Breach Exposes 2.5M Records
  • Watering Hole Attacks Push ScanBox Keylogger
  • Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms
  • Ransomware Attacks are on the Rise
  • Cybercriminals Are Selling Access to Chinese Surveillance Cameras
  • Twitter Whistleblower Complaint: The TL;DR Version
  • Firewall Bug Under Active Attack Triggers CISA Warning
  • Fake Reservation Links Prey on Weary Travelers
  • iPhone Users Urged to Update to Patch 2 Zero-Days
  • Google Patches Chrome’s Fifth Zero-Day of the Year

Trusted Sec

  • SpooNMAP Grows Up: Findings, Local LLM Detection, and a Whole Lot Less Waiting
  • We've Seen This Movie: The OT/IT Technology Divide
  • AI Offense is Not Noclip Mode
  • A Vault With No Treasure - CMMC Level 2 Compliance for Subcontractors With No CUI
  • The Art of Hunting Azure Cloud Secrets
  • TLS Encryption and Compliance
  • CCPA Update: Cybersecurity Requirements (Part 2)
  • CCPA Update: Who’s In Scope (Part 1)
  • AI Directives and AI Strategy Development
  • CMMC is (Not) Cancelled

App Sec

iSec Partners

  • Introducing opinel: Scout2's favorite tool
  • IAM user management strategy (part 2)
  • iSEC audit of MediaWiki
  • Work daily with enforced MFA-protected API access
  • Use and enforce Multi-Factor Authentication
  • iSEC reviews SecureDrop
  • Recognizing and Preventing TOCTOU Whitepaper
  • IAM user management strategy
  • Do not use your AWS root account
  • Announcing the AWS blog post series

Offensive Security

  • Road to OSCE3: Episodio 1 – OSEP
  • Knowing what not to attack
  • CVE-2026-72898: Critical Metabase Unauthenticated SQL Injection Vulnerability
  • Who Secures AI When It Touches Every Security Team?
  • Introducing the AI Red Teaming Upskill Program
  • What the Recent Water Systems Cyber Attacks Reveal About Critical Infrastructure Security
  • Why “AI Pentesting” is the Wrong Term (And Why We Need AI Red Teaming)
  • How Federal Agencies Can Turn Year-End Funding Into Long-Term Cyber Capability
  • The EU AI Act Deadline Is Approaching. Is Your Workforce Ready?
  • What Security Leaders Discover When They Train Their Team in the Same Room

The Hacker News

  • Berlin Refuses to Pay Hackers Who Stole Data From the City's State Network
  • Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable
  • Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication
  • Android 17 Adds OS-Wide ECH to Hide Website Visits From Network Providers
  • ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body
  • 19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code
  • Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth
  • Key Reasons Why Identity Fabric Matters in 2026
  • Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL
  • China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access

Sysadmin

AWS Blog

  • Happy 20th Birthday, Amazon EC2
  • AWS Weekly Roundup: Student Rewards on AWS Builder Center, Local Zone in Las Vegas, and …
  • AWS Glue 6.0 now available with 30% lower price and full Apache Iceberg v3 support
  • In the works: AWS Builder Lofts in Berlin, Hyderabad, and São Paulo
  • AWS Weekly Roundup: EC2 application status checks, IAM role manager, OpenAI Daybreak on Bedrock, and …
  • AWS Weekly Roundup: AWS Heroes Summit, Web Search on Amazon Bedrock, Dogwood, Kiro Crew, and …
  • Runtime instances: persistent compute for production AI agents on Amazon Bedrock AgentCore
  • Amazon DynamoDB now supports real-time vector search at any scale
  • AWS Weekly Roundup: Price reduction of GPT models in Bedrock, CloudWatch managed collectors for Prometheus …
  • AWS Weekly Roundup: Local Zone in Athens, Claude Opus 5 on AWS, Lambda durable execution …

Cyberciti

  • Download of the day: GIMP 3.0 is FINALLY Here!
  • Ubuntu to Explore Rust-Based “uutils” as Potential GNU Core Utilities Replacement
  • Critical Rsync Vulnerability Requires Immediate Patching on Linux and Unix systems
  • ZFS Raidz Expansion Finally, Here in version 2.3.0
  • lnav – Awesome terminal log file viewer for Linux and Unix
  • sttr – Awesome Linux & Unix tool for transformation of the string
  • How to block AI Crawler Bots using robots.txt file
  • Debian Linux 12.1 released with Security Updates
  • Setting up VSCode for Ansible Lightspeed AI in Ubuntu 22.04 desktop
  • How to upgrade FreeBSD 13.1 to 13.2 release

Distro Watch

  • Distribution Release: openKylin 3.0
  • Distribution Release: EndeavourOS 2026.08.15
  • Distribution Release: Ubuntu 26.04.1
  • Distribution Release: Butterbian 0.4.0
  • Distribution Release: NawaOS 2.0
  • Development Release: Haiku R1 Beta 6
  • Distribution Release: Armbian 26.8.3
  • Distribution Release: Vanilla OS 3
  • DistroWatch Weekly, Issue 1187
  • Distribution Release: PorteuX 2.8

Netflix Techblog

  • MAPS: Netflix’s Multimodal Asset Personalization at Scale
  • A Tale of Two Flink Autoscalers
  • How and Why Netflix Built a Real-Time Distributed Graph: Part 3 — Querying the graph …
  • Modeling Device Capabilities for Analytics
  • GenRec: Towards LLM-Native Recommendation at Netflix
  • In-House LLM Serving at Netflix
  • Building Service Topology at Scale: Architecture, Challenges, and Lessons Learned
  • GenPage: Towards End-to-End Generative Homepage Construction at Netflix
  • Toward More Controllable AI Video Editing: An Early Research Exploration at Netflix
  • How Netflix Simplified Batch Compute with Kueue

Reddit: /r/linux

  • The playstation finally running kernel 2.4.0
  • postmarketOS Linux booted on iPhone 6S
  • Debian Votes To Allow "Responsible Use Of Generative AI"
  • Debian Not banning AI - Proposal 5: Responsible Use of Generative AI wins GR vote
  • 8BitDo announce 'Ultimate Software Online' to update controllers in your browser to help Linux gamers
  • Artix Linux drops support for XLibre
  • Greg K-H (@[email protected]): CVEs fixed per Kernel Release over time
  • Patches Provide For Much Faster In-Kernel Zstd Due To Embarrassingly Bad Inefficiency
  • IBM Remote Supervisor Adapter Driver Removed for Linux 7.3
  • Announcing €500K Sovereign Tech Agency Investment in Flatpak

Stack Exchange: Security

  • Is this claim about firmware security true?
  • Changing the wazuh cluster administrator password with FreeIPA LDAP authentication [closed]
  • Report IP address for scam activity [closed]
  • Is monkey-patching fetch/XHR/sendBeacon/WebSocket a sound way to build a client-side outbound-request firewall?
  • MsfVenom generated shellcode fails when using it in buffer overflow
  • How to exploit Object.assign in Express/Mongoose application?
  • If you downloaded a video file that could potentially contain malware but it didn’t finish …
  • How to get a 12 bytes authentication tag in AES-GCM
  • Passing user identity to a different REST service
  • Windows controlled folder access to secure Chrome cookies?

Tech News

Ars Technica

  • Authorities arrest 2 alleged members of prolific hacking group TeamPCP
  • Claude, Codex, and Hermes installed unowned code inside corporate networks
  • How OpenAI let a mob of LLM agents game a test and ransack Hugging Face
  • AI agents meant to replace Meta workers made “large-scale, disruptive actions”
  • Inaudible sounds used to fingerprint browsers catch AliExpress red-handed
  • Waymo doubles spending on lobbying in robotaxi battle with Uber
  • Grok exfiltrates user data when malicious instructions are encrypted
  • Microsoft Copilot reveals secret input that allowed it to be hacked
  • Nvidia discloses $21B stake in SpaceX
  • Vulnerability giving attackers full control of Macs is under active exploitation

Tech Crunch

  • How I Get Free Traffic from ChatGPT in 2025 (AIO vs SEO)
  • Top 10 AI Tools That Will Transform Your Content Creation in 2025
  • LimeWire AI Studio Review 2023: Details, Pricing & Features
  • Top 10 AI Tools in 2023 That Will Make Your Life Easier
  • Top 10 AI Content Generator & Writer Tools in 2022
  • Beginner Guide to CJ Affiliate (Commission Junction) in 2022
  • TOP 11 AI MARKETING TOOLS YOU SHOULD USE (Updated 2022)
  • Most Frequently Asked Questions About Affiliate Marketing
  • What is Blockchain: Everything You Need to Know (2022)
  • ProWritingAid VS Grammarly: Which Grammar Checker is Better in (2022) ?

The Verge

  • Google further buries search results under AI mode
  • Xbox CEO calls Project Helix a ‘family of devices’
  • Save hundreds on a TCL mini-LED TV with quantum dots and high refresh rate
  • Trump’s EPA wants to let data centers hide their air pollution
  • DLSS 5 leaked and modders are putting Nvidia’s AI effects on everything
  • The iPhone Fold could make concerts even worse
  • Apple TV now costs $14.99 a month after its fourth price hike in four years
  • Apple TV’s sci-fi thriller Dark Matter gets even trippier in season 2
  • Anthropic was illegally blacklisted by the Trump administration, court rules
  • The GTA VI ‘extended look’ is now streaming on YouTube
  • Back to top
  • RSS
  • GitHub