How "Strengthening Crypto" Broke Authentication: FreshRSS and bcrypt's 72-Byte Limit
As part of our CVE monitoring, we came across GHSA-pcq9-mq6m-mvmp (CVE-2025-68402), an authentication bypass in FreshRSS, a self-hosted RSS aggregator. It ...
A commit meant to "strengthen the crypto" in FreshRSS ended up removing the need for a correct password.
Why?
Longer SHA-256 nonce + bcrypt truncation at 72 bytes.
A nice example of why secure systems are about composition, not just stronger primitives.
pentesterlab.com/blog/freshrs...
10.03.2026 08:54
๐ 9
๐ 5
๐ฌ 0
๐ 1
Defuddle now has a website!
This means you can use Defuddle anywhere to get the main content of a page in Markdown format.
You can simply add "defuddle.md" before any URL, use it via curl, Skills, CLI, or add it to your app via NPM.
04.03.2026 16:02
๐ 217
๐ 27
๐ฌ 9
๐ 2
24.02.2026 16:59
๐ 283
๐ 57
๐ฌ 1
๐ 2
Dropped a piece of command strip tape on the ground and mine gobbled it up ๐ซ
Luckily after a day or two of random dry coughing all symptoms stopped.
Love these little guys but man do they make you worry sometimes!
25.02.2026 12:41
๐ 1
๐ 0
๐ฌ 0
๐ 0
I worked really hard for this meme
25.02.2026 10:49
๐ 130
๐ 13
๐ฌ 3
๐ 0
GitHub - spaceraccoon/vulnerability-spoiler-alert-action: GitHub Action to alert on security patches before the CVE drops.
GitHub Action to alert on security patches before the CVE drops. - spaceraccoon/vulnerability-spoiler-alert-action
Vulnerability Spoiler Alert Action by @spaceraccoonsec
It monitors repositories and uses Claude to detect patching of security vulns. This early warning can give security teams more time to patch before the CVE drops.
GitHub repo๐
24.02.2026 10:36
๐ 0
๐ 1
๐ฌ 0
๐ 0
The Missing Semester of your CS education [MIT IAP 2026] - https://missing.csail.mit.edu
In January, @anishathalye.bsky.social, @josejg.bsky.social, and I returned to @csail.mit.edu to teach Missing Semester, a class on topics we miss from most CS programsโtools and techniques that everyone should know, like Bash, Git, CI, and AI tools. Today, weโre releasing the course for free online!
19.02.2026 16:47
๐ 59
๐ 18
๐ฌ 1
๐ 4
Paged Out! #8 is out! pagedout.institute @pagedout.bsky.social
In "An AWKward Modem" (p. 28), I show how to write a tiny modem in 5 lines of AWK and shift it into the near-ultrasonic range. ๐
19.02.2026 20:13
๐ 4
๐ 3
๐ฌ 1
๐ 0
Cline CLI npm Package Compromised via Suspected Cache Poison...
A compromised npm publish token was used to push a malicious postinstall script in cline@2.3.0, affecting the popular AI coding agent CLI with 90k wee...
A compromised npm token was used to push an unauthorized postinstall script in cline@2.3.0, a popular AI coding agent CLI with 90k weekly downloads.
Big shoutout to @adnanthekhan.bsky.social whose research sniffed out the cache poisoning vulnerability! ๐ช
Details โ socket.dev/blog/cline-c...
18.02.2026 17:06
๐ 4
๐ 3
๐ฌ 0
๐ 1
โI want it to just workโ is the main requirement for 99% of people.
I totally get why too.
12.02.2026 00:43
๐ 1
๐ 0
๐ฌ 0
๐ 0
The Discord situation is going to produce a lot more people that hate Matrix.
They will still use Discord but they will now also hate Matrix
11.02.2026 21:44
๐ 23
๐ 2
๐ฌ 1
๐ 2
11.02.2026 15:30
๐ 62
๐ 5
๐ฌ 2
๐ 0
Go 1.26 has a lot to love, including significant performance improvements that are completely transparent to Go developers. Just upgrade and your Go programs run faster -- no other changes required!
10.02.2026 23:41
๐ 34
๐ 5
๐ฌ 0
๐ 1
OpenClaw Skill Marketplace Emerges as Active Malware Vector ...
Security researchers report widespread abuse of OpenClaw skills to deliver info-stealing malware, exposing a new supply chain risk as agent ecosystems...
โ ๏ธ๐ค Weโre entering a new era of malicious workflows.
OpenClaw skills show how easily agent workflows can be abused once theyโre trusted to execute.
A closer look at this emerging class of supply chain attack:
socket.dev/blog/opencla...
10.02.2026 05:04
๐ 1
๐ 1
๐ฌ 0
๐ 1
Security - OpenClaw
Openclaw (Clawdbot) is cool and all but itโs also risky.
Make sure you get your bot audited with some better security practices ๐ย
https://auth0.com/blog/five-step-guide-securing-moltbot-ai-agent/
10.02.2026 11:03
๐ 0
๐ 1
๐ฌ 0
๐ 0
The Scam Ad Machine
Nearly one in three Meta ads found to point to a scam, phishing or malware
Dear f***ing lord!
Nearly one every three Meta ads showed in the EU and UK over 23 days pointed to online scams
This should be the easiest layup for govt agencies in the history of enforcements
www.gendigital.com/blog/insight...
03.02.2026 11:57
๐ 126
๐ 59
๐ฌ 4
๐ 7
Our pentesting agent found a 1-click ATO to RCE in @moltbot Gateway Control UI in under 2 hours.
Local instances can also be exploited with one click.
Patched in main, update now.
Watch the exploit ๐
29.01.2026 16:38
๐ 0
๐ 1
๐ฌ 1
๐ 0
Got the final piece beautifully rendered and ready to be sent off for the 10qty SLM printโฆ
But then I ran across the mass-market cut ones from China for $1.00/pc ๐ญ Why do they have to be so insanely cheap.
23.01.2026 19:55
๐ 1
๐ 0
๐ฌ 0
๐ 0
23.01.2026 19:53
๐ 1
๐ 0
๐ฌ 0
๐ 0
CVE-2026-23993: JWT authentication bypass in HarbourJwt via โunknown algโ
I didn't know Harbour even existed as a language when I found this bug. The fun part is that I also ...
๐ฅ CVE-2026-23993: HarbourJwt JWT auth bypass via unknown alg.
Not just alg=none: unsupported alg => empty signature, so forged token header.payload. passes.
Write-up + fix: pentesterlab.com/blog/cve-202...
21.01.2026 22:12
๐ 6
๐ 6
๐ฌ 0
๐ 1
๐๏ธ cURL stopped HackerOne bug bounty program due to excessive slop reports
๐ https://github.com/curl/curl/pull/20312
20.01.2026 12:32
๐ 0
๐ 1
๐ฌ 0
๐ 0
๐๏ธ Research Worth Reading Week 03/2026
๐ https://pentesterlab.com/blog/research-worth-reading-week03-2026
19.01.2026 12:32
๐ 0
๐ 1
๐ฌ 0
๐ 0
HTB: HackNet
HackNet hosts a social media site for hackers built with Django. Iโll find an HTML injection in the username field that, combined with how the likes page renders usernames, leads to server-side template injection. While Django templates are restrictive, Iโll use the SSTI to dump user data including plaintext passwords, finding one user whose email reveals their Linux username. After SSHing in, Iโll discover Djangoโs FileBasedCache uses pickle serialization with a world-writable cache directory. By replacing cache files with a malicious pickle payload, Iโll get a shell as the web user. From there, Iโll crack a GPG key password to decrypt database backups, finding a password shared in messages that works for root.
HackNet from HackTheBox features SSTI in Django templates to leak user credentials, pickle deserialization via FileBasedCache with world-writable directory, and GPG key cracking to recover database backups containing the root password.
17.01.2026 15:06
๐ 3
๐ 2
๐ฌ 0
๐ 0