Skip to content
EN

Security

Vulnerabilities, exploits, hardening and security engineering.

17 links, newest first.

Get the weekly briefing

The best new links of the topics you pick, summarized with the source. At most one email a week.

Topics: Security

Before the first issue we email you to confirm; leaving takes one click. Sent with CommsHarbor. Privacy

  1. SecurityArticle

    Post claims iOS IPA decryption without a physical iPhone

    The post links to a report about decrypting FairPlay-protected iOS IPAs, claiming the process works without a physical iPhone or jailbreak.

    The claim may interest engineers studying iOS app protection and reverse engineering.

  2. How to Back Up High-Value Secret Keys

    The post links to a paper about backing up high-value secret keys.

    Secret-key backup is a security engineering concern for systems that depend on valuable keys.

  3. SecurityRepository

    Practical cryptography course covers PIR and TLS

    A practical cryptography course covering PIR in practice, TLS 1.3, post-quantum integration, and TLS attestation.

    Engineers can use it to explore practical cryptography topics and TLS features.

  4. SecurityArticle

    Signing TLS Handshakes Inside a TPM in Go

    The article shows how to use a client certificate whose private key stays in a TPM, covering what Go's crypto/tls requires and the cost per handshake.

    Useful for engineers evaluating TPM-backed client keys and their performance impact in Go TLS connections.

  5. SecurityArticle

    Decrypt TLS 1.3 HTTPS traffic in Wireshark

    The blog explains how to use SSLKEYLOGFILE to capture TLS key information and load it into Wireshark to inspect HTTP requests in captured HTTPS traffic.

    Useful for engineers troubleshooting and analyzing HTTPS traffic they are authorized to inspect.

  6. Study reports code overlap between Geedge leak and Great Firewall

    The post links to a USENIX Security paper whose authors report source-code overlap between leaked Geedge Networks code and China's Great Firewall, including DNS and RST injection behavior.

    The reported overlap may help engineers understand how network filtering systems implement traffic injection.

  7. IO Factory simulates AI-enabled influence campaigns

    The paper introduces IO Factory, an AI-driven framework for simulating information and influence campaigns as integrated, traceable processes. It describes coordinated AI agents that adapt to platform feedback and disguise campaigns as ordinary social interaction.

    Security teams can use the work to study coordinated, adaptive influence campaigns that are difficult to detect from individual messages.

  8. ExploitGym evaluates AI agents’ ability to exploit vulnerabilities

    ExploitGym studies whether AI agents can turn security vulnerabilities into concrete impacts such as unauthorized file access or code execution. The task requires low-level program reasoning, runtime adaptation, and sustained progress.

    It offers a way to evaluate AI agents’ capabilities for converting vulnerabilities into real attacks.

  9. SecurityPost on X

    How reverse-proxy phishing can capture MFA session cookies

    The post describes phishing kits that proxy a victim’s login and MFA interaction with a real service, then intercept the resulting session cookie. It names Evilginx, Modlishka, and Muraena.

    Engineers can use this attack pattern to inform phishing defenses and authentication design.

  10. SecurityRepository

    obfus.h: Compile-time obfuscation for C

    obfus.h is a macro header for compile-time C obfuscation on Windows x86/x64 using tcc. The post says it supports virtualization, anti-debugging, and control-flow obfuscation.

    Engineers can assess its code-mutation techniques when evaluating software protection and reverse-engineering resistance.

  11. Practical Privacy and Availability Attacks on 4G/LTE

    A 2015 paper by Altaf Shaik et al. examines practical attacks against privacy and availability in 4G/LTE mobile communication systems.

    Relevant to engineers assessing privacy and availability risks in mobile networks.

  12. SecurityPost on X

    Device-code phishing is not specific to Wi-Fi

    The author argues that device-code authentication phishing can happen over Ethernet or the internet, not only over Wi-Fi.

    It cautions engineers against treating device-code phishing as a Wi-Fi-specific risk.

  13. SecurityPost on X

    uv can check packages against OSV before installation

    Setting `UV_MALWARE_CHECK=1` makes uv cross-reference the OSV database before installing packages from a remote registry and block packages reported as malware.

    This adds a malware check before package installation from remote registries.

  14. SecurityPost on X

    Prompt injection in AI-assisted binary reverse engineering

    The post describes Naval Postgraduate School research on embedding short prompt-injection strings in C binaries to influence LLM-powered reverse-engineering agents during Ghidra analysis. It says the researchers used an AutoDAN-style genetic algorithm to generate payloads that fit Ghidra’s…

    Engineers using AI for binary analysis should consider that strings in analyzed binaries can act as untrusted instructions to the model.

  15. SecurityPost on X

    Windows access tokens and kernel privilege escalation

    The post describes the Windows kernel _TOKEN structure, which holds identity and security attributes for processes and threads. It explains that privilege-escalation exploits have historically gained SYSTEM privileges by replacing a process token.

    Understanding tokens helps engineers reason about Windows access control and privilege-escalation risks.

  16. SecurityPost on X

    Bootloader Security: Attack Surfaces, Detection, and Defenses

    A paper covers bootloader attack surfaces, vulnerability detection techniques, and defenses across firmware, OS, and monolithic bootloaders.

    Engineers can use its overview to assess bootloader risks and defensive approaches across different boot architectures.

  17. SecurityPost on X

    Collection of Prompt Injection Vectors and Strategies

    The post points to a collection of prompt injection vectors and strategies, with examples.

    It may help engineers identify prompt injection techniques when assessing or hardening systems.

Build with AgentLog

List your MCP, skill or plugin

Reach the engineers who read these briefings.

Sponsor AgentLog

Footer, sidebar or featured slot for 30 days.

From US$ 60

See the slots

Send your own newsletter

CommsHarbor keeps contacts, consent and one-click unsubscribe together.

Free workspace

Open CommsHarbor