Entry Thumbnail

AI in the Middle: Turning Web-Based AI Services into C2 Proxies & The Future Of AI Driven Attacks

AI is rapidly becoming embedded in day-to-day enterprise workflows, inside browsers, collaboration suites, and developer tooling. As a result, AI service domains increasingly blend into normal corporate traffic, often allowed by default and rarely treated as sensitive egress. Threat actors are already capitalizing on this shift. Across the malware ecosystem, […]

Posted by
Entry Thumbnail

Building a Secure Electron Auto-Updater

# Building a Secure Electron Auto-Updater 16 Feb 2026 – Posted by Michael Pastor ## Introduction In cooperation with the Polytechnic University of Valencia and Doyensec, I spent over six months during my internship in a research that combines theoretical foundations in code signing and secure update designs with a […]

Posted by
Entry Thumbnail

Security Researchers Find Vulnerabilities in Mental Health Apps; One With Millions of Users May Leak Therapy Notes

# Security Researchers Find Vulnerabilities in Mental Health Apps; One With Millions of Users May Leak Therapy Notes Your AI therapist’s notes may be worth more than your credit card number on the dark web. Security analysis reveals a potential new frontier for cyber espionage. Oversecured, a mobile application security […]

Posted by
Entry Thumbnail

Top 10 web hacking techniques of 2025

Director of Research **Published:** 05 February 2026 at 15:28 UTC **Updated:** 05 February 2026 at 15:30 UTC Welcome to the Top 10 Web Hacking Techniques of 2025, the 19th edition of our annual community-powered effort to identify the most innovative must-read web security research published in the last year. This […]

Posted by
Entry Thumbnail

Pickling the Mailbox: A Deep Dive into CVE-2025-20393

## TL;DR In December 2025, Cisco published https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sma-attack-N9bf4 addressing CVE-2025-20393, a critical vulnerability (CVSS 10.0) affecting Cisco Secure Email Gateway and Secure Email and Web Manager. The advisory was notably sparse on technical details, describing only “Improper Input Validation” (CWE-20). We decided to dig deeper. Through reverse engineering and code […]

Posted by