# Security research

Published articles for Security research.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## When scanners miss the attack: how Cloudflare Client-Side Security protects storefronts

DevFeed: [When scanners miss the attack: how Cloudflare Client-Side Security protects storefronts](<https://devfeed.tech/articles/when-scanners-miss-the-attack-how-cloudflare-client-side-security-protects-storefronts-31481.md>)

Original publisher: [Read original article](<https://blog.cloudflare.com/client-side-security-finds-4-malicious-campaigns/>)

Author: Denzil Correa

Published: 2026-09-16T20:06:17Z

Content type: article

Language: en

Sources: [Cloudflare Blog](<https://devfeed.tech/sources/cloudflare-blog.md>)

Topics: [Cloudflare](<https://devfeed.tech/topics/cloudflare.md>), [Machine Learning, Security Attacks](<https://devfeed.tech/topics/machine-learning-security-attacks.md>), [Security](<https://devfeed.tech/topics/security.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [client-side-security](<https://devfeed.tech/tags/client-side-security.md>), [cloudflare](<https://devfeed.tech/tags/cloudflare.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [developer-platform](<https://devfeed.tech/tags/developer-platform.md>), [developers](<https://devfeed.tech/tags/developers.md>), [ecommerce](<https://devfeed.tech/tags/ecommerce.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [machine-learning](<https://devfeed.tech/tags/machine-learning.md>), [malicious-javascript](<https://devfeed.tech/tags/malicious-javascript.md>), [page-shield](<https://devfeed.tech/tags/page-shield.md>), [security](<https://devfeed.tech/tags/security.md>), [security-research](<https://devfeed.tech/tags/security-research.md>), [virustotal](<https://devfeed.tech/tags/virustotal.md>), [workers-ai](<https://devfeed.tech/tags/workers-ai.md>)

### AI overview

Cloudflare describes how its Client-Side Security machine learning model detected four malicious JavaScript operations involving eight payloads in live storefront traffic. The post says humans verified the findings after automated detection, while most payloads were absent from VirusTotal and received no malicious verdict from URLScan.

### Source excerpt

A modern storefront can look healthy while malicious JavaScript quietly siphons revenue, hijacks clicks, or rewrites analytics. See how Cloudflare's machine learning models surface evasive client-side attacks for analyst investigation.

## A Threat Hunter's Guide to Detecting Malicious Activity in GitHub Audit Logs

DevFeed: [A Threat Hunter's Guide to Detecting Malicious Activity in GitHub Audit Logs](<https://devfeed.tech/articles/mapping-out-your-unknown-a-threat-hunter-s-guide-to-github-30894.md>)

Original publisher: [Read original article](<https://securitylabs.datadoghq.com/articles/mapping-out-your-unknown-threat-hunters-guide-to-github/>)

Author: Julie Agnes Sparks, Juvenal Araujo

Published: 2026-09-16T00:00:00Z

Content type: article

Language: en

Sources: [Datadog Security Labs](<https://devfeed.tech/sources/datadog-security-labs.md>)

Topics: [GitHub](<https://devfeed.tech/topics/github.md>), [Threat Hunting & Intel](<https://devfeed.tech/topics/threat-hunting-intel.md>), [Security](<https://devfeed.tech/topics/security.md>), [Logging](<https://devfeed.tech/topics/logging.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [personal access token](<https://devfeed.tech/topics/personal-access-token.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [github](<https://devfeed.tech/tags/github.md>), [logging](<https://devfeed.tech/tags/logging.md>), [oauth](<https://devfeed.tech/tags/oauth.md>), [personal-access-token](<https://devfeed.tech/tags/personal-access-token.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [security](<https://devfeed.tech/tags/security.md>), [security-research](<https://devfeed.tech/tags/security-research.md>)

### AI overview

This article examines threats targeting GitHub organizations, including compromised accounts, personal access tokens, OAuth tokens, leaked secrets, phishing, and malicious extensions or OAuth apps. It describes GitHub audit-log queries and behaviors that can help detect account compromise, reconnaissance, and source-code exfiltration.

### Source excerpt

In this post, we walk through different threats to GitHub and how to detect them.

## Modern App Protection Requires Polymorphism | Guardsquare

DevFeed: [Modern App Protection Requires Polymorphism | Guardsquare](<https://devfeed.tech/articles/modern-app-protection-requires-polymorphism-guardsquare-26311.md>)

Original publisher: [Read original article](<https://www.guardsquare.com/blog/polymorphic-mobile-app-protection>)

Author: Jason Cortlund - Technical Marketing Writer

Published: 2026-08-18T13:45:43Z

Content type: article

Language: en

Sources: [Guardsquare Blog](<https://devfeed.tech/sources/guardsquare-blog.md>)

Topics: [Mobile](<https://devfeed.tech/topics/mobile.md>), [Mobile Security](<https://devfeed.tech/topics/mobile-security.md>), [Polymorphism](<https://devfeed.tech/topics/polymorphism.md>), [Security](<https://devfeed.tech/topics/security.md>), [Development](<https://devfeed.tech/topics/development.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Large Language Model](<https://devfeed.tech/topics/llm.md>)

Tags: [agentic-ai](<https://devfeed.tech/tags/agentic-ai.md>), [ai](<https://devfeed.tech/tags/ai.md>), [development](<https://devfeed.tech/tags/development.md>), [dexguard](<https://devfeed.tech/tags/dexguard.md>), [ixguard](<https://devfeed.tech/tags/ixguard.md>), [large-language-models-llms](<https://devfeed.tech/tags/large-language-models-llms.md>), [mobile](<https://devfeed.tech/tags/mobile.md>), [polymorphism](<https://devfeed.tech/tags/polymorphism.md>), [protection](<https://devfeed.tech/tags/protection.md>), [reverse-engineering](<https://devfeed.tech/tags/reverse-engineering.md>), [security](<https://devfeed.tech/tags/security.md>), [security-research](<https://devfeed.tech/tags/security-research.md>), [thought-leadership](<https://devfeed.tech/tags/thought-leadership.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

The article argues that mobile app protection should use polymorphism, with protections changing for each application build. It links this approach to the risks created by development speed, AI-generated code, and scalable reverse-engineering attacks.

### Source excerpt

According to credit reporting agency Equifax, "...mobile app security is often neglected by developers -- making apps more vulnerable to fraud." The reason for this is quite simple for most organizations: development speed is the dominant priority. In fact, 79% of mobile developers cite time-to-market pressure as the top barrier to stronger protection.

## Announcing the CIS Benchmark for CockroachDB v25.x

DevFeed: [Announcing the CIS Benchmark for CockroachDB v25.x](<https://devfeed.tech/articles/announcing-the-cis-benchmark-for-cockroachdb-v25-x-23757.md>)

Original publisher: [Read original article](<https://cockroachlabs.com/blog/cis-benchmark-cockroachdb-security>)

Author: Adam Brennick,Ayog Mohanty

Published: 2026-07-14T00:00:00Z

Content type: release

Language: en

Sources: [Cockroach Labs](<https://devfeed.tech/sources/cockroach-labs.md>)

Topics: [Benchmark](<https://devfeed.tech/topics/benchmark.md>), [CockroachDB](<https://devfeed.tech/topics/cockroachdb.md>), [Security](<https://devfeed.tech/topics/security.md>), [Cockroach Labs](<https://devfeed.tech/topics/cockroach-labs.md>), [configuration](<https://devfeed.tech/topics/configuration.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Database](<https://devfeed.tech/topics/database.md>), [Self-hosted](<https://devfeed.tech/topics/self-hosted.md>)

Tags: [announce](<https://devfeed.tech/tags/announce.md>), [benchmark](<https://devfeed.tech/tags/benchmark.md>), [cockroach-labs](<https://devfeed.tech/tags/cockroach-labs.md>), [cockroachdb](<https://devfeed.tech/tags/cockroachdb.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [configuration](<https://devfeed.tech/tags/configuration.md>), [fedramp](<https://devfeed.tech/tags/fedramp.md>), [government](<https://devfeed.tech/tags/government.md>), [hipaa](<https://devfeed.tech/tags/hipaa.md>), [pci-dss](<https://devfeed.tech/tags/pci-dss.md>), [published](<https://devfeed.tech/tags/published.md>), [security](<https://devfeed.tech/tags/security.md>), [security-best-practices](<https://devfeed.tech/tags/security-best-practices.md>), [security-research](<https://devfeed.tech/tags/security-research.md>), [self-hosted](<https://devfeed.tech/tags/self-hosted.md>), [standard](<https://devfeed.tech/tags/standard.md>)

### AI overview

The Center for Internet Security has published the CIS CockroachDB v25.x Benchmark, providing a consensus-driven security configuration guide for self-hosted CockroachDB deployments. The article explains how the benchmark can support standardized security practices, audits, compliance reviews, and production configuration validation.

### Source excerpt

We're proud to announce that the Center for Internet Security (CIS) has published the CIS CockroachDB v25.x Benchmark.

## The triage is the product: running AI agents against Ethereum's protocol code

DevFeed: [The triage is the product: running AI agents against Ethereum's protocol code](<https://devfeed.tech/articles/the-triage-is-the-product-running-ai-agents-against-ethereum-s-protocol-code-17227.md>)

Original publisher: [Read original article](<https://blog.ethereum.org/en/2026/07/09/triage-is-the-product>)

Author: Nikos Baxevanis

Published: 2026-07-09T00:00:00Z

Content type: article

Language: en

Sources: [Ethereum Foundation Blog](<https://devfeed.tech/sources/ethereum-foundation-blog.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Ethereum](<https://devfeed.tech/topics/ethereum.md>), [Security](<https://devfeed.tech/topics/security.md>), [AI research agents](<https://devfeed.tech/topics/ai-research-agents.md>), [Code](<https://devfeed.tech/topics/code.md>), [P2P](<https://devfeed.tech/topics/p2p.md>)

Tags: [agents](<https://devfeed.tech/tags/agents.md>), [ai](<https://devfeed.tech/tags/ai.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [cve](<https://devfeed.tech/tags/cve.md>), [ethereum](<https://devfeed.tech/tags/ethereum.md>), [protocol](<https://devfeed.tech/tags/protocol.md>), [research](<https://devfeed.tech/tags/research.md>), [research-development](<https://devfeed.tech/tags/research-development.md>), [security](<https://devfeed.tech/tags/security.md>), [security-research](<https://devfeed.tech/tags/security-research.md>)

### AI overview

The Ethereum Foundation's Protocol Security team describes how it uses coordinated AI agents to audit Ethereum protocol code. The article focuses on organizing agent work, validating candidate bugs, and reducing false positives. It reports a remotely triggerable panic in libp2p's gossipsub, disclosed as CVE-2026-34219.

### Source excerpt

Notes from the Ethereum Foundation's Protocol Security team on running coordinated AI agents against real protocol code, including how we organize the work, what holds up under scrutiny, and what client teams and security researchers can take from it. This post stands on its own; later posts will go deeper...

## Why Vulnerability Clearinghouses Alone Cannot Secure Open Source

DevFeed: [Why Vulnerability Clearinghouses Alone Cannot Secure Open Source](<https://devfeed.tech/articles/summer-of-clearinghouses-13244.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/summer-of-clearinghouses>)

Published: 2026-07-05T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [data](<https://devfeed.tech/topics/data.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Security](<https://devfeed.tech/topics/security.md>), [NVD](<https://devfeed.tech/topics/nvd.md>), [Unix](<https://devfeed.tech/topics/unix.md>)

Tags: [akrites](<https://devfeed.tech/tags/akrites.md>), [athena](<https://devfeed.tech/tags/athena.md>), [chainguard-libraries](<https://devfeed.tech/tags/chainguard-libraries.md>), [data](<https://devfeed.tech/tags/data.md>), [ibm-red-hat-project-lightwell](<https://devfeed.tech/tags/ibm-red-hat-project-lightwell.md>), [nvd](<https://devfeed.tech/tags/nvd.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [press-release](<https://devfeed.tech/tags/press-release.md>), [secure-open-source](<https://devfeed.tech/tags/secure-open-source.md>), [security](<https://devfeed.tech/tags/security.md>), [security-research](<https://devfeed.tech/tags/security-research.md>), [vulnerability-clearinghouse](<https://devfeed.tech/tags/vulnerability-clearinghouse.md>), [vulnerability-data](<https://devfeed.tech/tags/vulnerability-data.md>)

### AI overview

The article argues that vulnerability clearinghouses are primarily pools of data and are not the most important part of securing open source. It emphasizes actuation--turning findings into fixes--along with trusted builds and secure-by-design software.

### Source excerpt

Clearinghouses alone won't secure open source. Learn why actuation, trusted builds, and secure-by-design software matter more than vulnerability data.

## TP-Link Tapo C200: Hardcoded Keys, Buffer Overflows and Privacy in the Era of AI Assisted Reverse Engineering

DevFeed: [TP-Link Tapo C200: Hardcoded Keys, Buffer Overflows and Privacy in the Era of AI Assisted Reverse Engineering](<https://devfeed.tech/articles/tp-link-tapo-c200-hardcoded-keys-buffer-overflows-and-privacy-in-the-era-of-ai-assisted-reverse-engineering-41272.md>)

Original publisher: [Read original article](<https://www.evilsocket.net/2025/12/18/TP-Link-Tapo-C200-Hardcoded-Keys-Buffer-Overflows-and-Privacy-in-the-Era-of-AI-Assisted-Reverse-Engineering/>)

Author: Simone Margaritelli

Published: 2025-12-17T23:00:00Z

Content type: article

Language: en

Sources: [evilsocket](<https://devfeed.tech/sources/evilsocket.md>)

Topics: [Reverse Engineering](<https://devfeed.tech/topics/reverse-engineering.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [Embedded Systems](<https://devfeed.tech/topics/embedded-systems.md>), [Android](<https://devfeed.tech/topics/android.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-assisted-reverse-engineering](<https://devfeed.tech/tags/ai-assisted-reverse-engineering.md>), [android](<https://devfeed.tech/tags/android.md>), [assembly](<https://devfeed.tech/tags/assembly.md>), [aws](<https://devfeed.tech/tags/aws.md>), [china](<https://devfeed.tech/tags/china.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-2025-14299](<https://devfeed.tech/tags/cve-2025-14299.md>), [cve-2025-14300](<https://devfeed.tech/tags/cve-2025-14300.md>), [cve-2025-8065](<https://devfeed.tech/tags/cve-2025-8065.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [embedded-devices](<https://devfeed.tech/tags/embedded-devices.md>), [embedded-systems](<https://devfeed.tech/tags/embedded-systems.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [firmware](<https://devfeed.tech/tags/firmware.md>), [ghidra](<https://devfeed.tech/tags/ghidra.md>), [ghidramcp](<https://devfeed.tech/tags/ghidramcp.md>), [hardcoded-credentials](<https://devfeed.tech/tags/hardcoded-credentials.md>), [integer-overflow](<https://devfeed.tech/tags/integer-overflow.md>), [iot](<https://devfeed.tech/tags/iot.md>), [iot-security](<https://devfeed.tech/tags/iot-security.md>), [memory](<https://devfeed.tech/tags/memory.md>), [mips](<https://devfeed.tech/tags/mips.md>), [privacy](<https://devfeed.tech/tags/privacy.md>), [re](<https://devfeed.tech/tags/re.md>), [reverse-engineering](<https://devfeed.tech/tags/reverse-engineering.md>), [reversing](<https://devfeed.tech/tags/reversing.md>), [security](<https://devfeed.tech/tags/security.md>), [security-research](<https://devfeed.tech/tags/security-research.md>), [security-vulnerabilities](<https://devfeed.tech/tags/security-vulnerabilities.md>), [tapo-c200](<https://devfeed.tech/tags/tapo-c200.md>), [tapo-camera](<https://devfeed.tech/tags/tapo-camera.md>), [tp-link](<https://devfeed.tech/tags/tp-link.md>), [tplink](<https://devfeed.tech/tags/tplink.md>), [vulnerability-research](<https://devfeed.tech/tags/vulnerability-research.md>)

### AI overview

This article describes an AI-assisted reverse-engineering investigation of TP-Link Tapo C200 camera firmware. The author reports finding several security vulnerabilities affecting about 25,000 devices directly exposed on the internet, and discusses the tools and process used.

### Source excerpt

Hi friends and welcome to the last post for this year! Whenever someone asks me how to get started with reverse engineering, I always giv

## An overview of the PPPP protocol for IoT cameras

DevFeed: [An overview of the PPPP protocol for IoT cameras](<https://devfeed.tech/articles/an-overview-of-the-pppp-protocol-for-iot-cameras-36627.md>)

Original publisher: [Read original article](<https://palant.info/2025/11/05/an-overview-of-the-pppp-protocol-for-iot-cameras/>)

Author: Wladimir Palant

Published: 2025-11-05T15:11:36Z

Content type: article

Language: en

Sources: [Almost Secure](<https://devfeed.tech/sources/almost-secure.md>)

Topics: [Internet of things](<https://devfeed.tech/topics/iot.md>), [Protocol (disambiguation)](<https://devfeed.tech/topics/protocol.md>), [P2P](<https://devfeed.tech/topics/p2p.md>), [Reverse Engineering](<https://devfeed.tech/topics/reverse-engineering.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [cameras](<https://devfeed.tech/tags/cameras.md>), [firmware](<https://devfeed.tech/tags/firmware.md>), [iot](<https://devfeed.tech/tags/iot.md>), [network](<https://devfeed.tech/tags/network.md>), [p2p](<https://devfeed.tech/tags/p2p.md>), [protocol](<https://devfeed.tech/tags/protocol.md>), [reverse-engineering](<https://devfeed.tech/tags/reverse-engineering.md>), [security-research](<https://devfeed.tech/tags/security-research.md>), [servers](<https://devfeed.tech/tags/servers.md>), [tcp](<https://devfeed.tech/tags/tcp.md>)

### AI overview

An overview of the PPPP protocol used primarily by network-connected IoT cameras. The article explains that PPPP relies on central servers while allowing bulk data transfer through direct client-to-device connections, and describes device identifiers, connection establishment, fallback mechanisms, redundant servers, and related protocol research.

### Source excerpt

My previous article on IoT "P2P" cameras couldn't go into much detail on the PPPP protocol. However, there is already lots of security research on and around that protocol, and I have a feeling that there is way more to come. There are pieces of information on the protocol scattered throughout the web, yet every one approaching from a very specific narrow angle. This is my attempt at creating an overview so that other people don't need to start from scratch. While the protocol can in principle be used by any kind of device, it is mostly being used for network-connected cameras. It isn't really peer-to-peer as advertised but rather relies on central servers, yet the protocol allows to transfer the bulk of data via a direct connection between the client and the device. It's hard to tell how many users there are but there are lots of apps, I'm sure that I haven't found all of them. There are other protocols with similar approaches being used for the same goal. One is used by ThroughTek's Kalay Platform which has the interesting string "Charlie is the designer of P2P!!" in its codebase (32 bytes long, seems to be used as "encryption" key for some non-critical functionality). I recognize both the name and the "handwriting," it looks like PPPP protocol designer found a new home here. Yet PPPP seems to be still more popular than the competition, thanks to it being the protocol of choice for cheap low-end cameras. Disclaimer: Most of the information below has been acquired by analyzing public information as well as reverse engineering applications and firmware, not by observing live systems. Consequently, there can be misinterpretations. Contents The general design The network ports The device IDs The protocol variants CS2 Network Yi Technology iLnk HLP2P "Encryption" "Secret" messages Applications Changelog The general design The protocol's goal is to serve as a drop-in replacement for TCP. Rather than establish a connection to a known IP address (or a name to be resolved

## Ethereum Protocol Attackathon is Live

DevFeed: [Ethereum Protocol Attackathon is Live](<https://devfeed.tech/articles/ethereum-protocol-attackathon-is-live-17122.md>)

Original publisher: [Read original article](<https://blog.ethereum.org/en/2024/11/25/ethereum-protocol-attackathon>)

Author: EF Protocol Support

Published: 2024-11-25T00:00:00Z

Content type: release

Language: en

Sources: [Ethereum Foundation Blog](<https://devfeed.tech/sources/ethereum-foundation-blog.md>)

Topics: [Ethereum](<https://devfeed.tech/topics/ethereum.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Protocol (disambiguation)](<https://devfeed.tech/topics/protocol.md>)

Tags: [announce](<https://devfeed.tech/tags/announce.md>), [audit](<https://devfeed.tech/tags/audit.md>), [competition](<https://devfeed.tech/tags/competition.md>), [ethereum](<https://devfeed.tech/tags/ethereum.md>), [launch](<https://devfeed.tech/tags/launch.md>), [protocol](<https://devfeed.tech/tags/protocol.md>), [security](<https://devfeed.tech/tags/security.md>), [security-research](<https://devfeed.tech/tags/security-research.md>)

### AI overview

The Ethereum Foundation announces the first Ethereum protocol Attackathon, a crowdsourced security audit competition hosted by Immunefi. Running from November 25 to January 20, it offers a $1.5 million reward pool and includes educational walkthroughs before researchers search for impactful, rule-compliant vulnerabilities.

### Source excerpt

The Protocol Security Research Team and the Ecosystem Funding Initiative at the Ethereum Foundation are pleased to announce the launch of the first Ethereum protocol Attackathon with a reward pool of $1,500,000, hosted by Immunefi. The attackathon runs between November 25th and January 20th and aims to enhance the security...

## How libuv CVE-2024-24806 can evade scanners and expose internal services

DevFeed: [How libuv CVE-2024-24806 can evade scanners and expose internal services](<https://devfeed.tech/articles/unpacking-libuv-s-cve-2024-24806-software-dark-matter-will-go-under-the-radar-not-in-chainguard-images-tho-13306.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/unpacking-libuvs-cve-2024-24806-software-dark-matter-will-go-under-the-radar-not-in-chainguard-images-tho>)

Published: 2024-02-16T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [software dark matter](<https://devfeed.tech/topics/software-dark-matter.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>)

Tags: [container](<https://devfeed.tech/tags/container.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-2024-24806](<https://devfeed.tech/tags/cve-2024-24806.md>), [false-negative](<https://devfeed.tech/tags/false-negative.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [libuv](<https://devfeed.tech/tags/libuv.md>), [sbom](<https://devfeed.tech/tags/sbom.md>), [security](<https://devfeed.tech/tags/security.md>), [security-research](<https://devfeed.tech/tags/security-research.md>), [software-dark-matter](<https://devfeed.tech/tags/software-dark-matter.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

The article examines CVE-2024-24806, a libuv vulnerability caused by hostname truncation without a terminating null byte when the hostname exceeds 256 characters. It explains how the flaw can enable SSRF and unauthorized access to internal APIs, including in multi-pod Kubernetes environments, and why vendored or bundled components may evade scanners and SBOM tools.

### Source excerpt

Uncover Chainguard's approach to detecting and neutralizing hidden threats like CVE-2024-24806 in container environments.

## Using Burp Suite Bambdas to Find Unusual HTTP Endpoints and Vulnerabilities

DevFeed: [Using Burp Suite Bambdas to Find Unusual HTTP Endpoints and Vulnerabilities](<https://devfeed.tech/articles/finding-that-one-weird-endpoint-with-bambdas-7678.md>)

Original publisher: [Read original article](<https://portswigger.net/research/finding-that-one-weird-endpoint-with-bambdas>)

Author: James Kettle

Published: 2023-12-12T14:11:17Z

Content type: article

Language: en

Sources: [PortSwigger Research](<https://devfeed.tech/sources/portswigger-research.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [HTTP](<https://devfeed.tech/topics/http.md>), [servers](<https://devfeed.tech/topics/servers.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [false-positives](<https://devfeed.tech/tags/false-positives.md>), [http](<https://devfeed.tech/tags/http.md>), [security](<https://devfeed.tech/tags/security.md>), [security-research](<https://devfeed.tech/tags/security-research.md>)

### AI overview

PortSwigger Research describes using Burp Suite Bambdas to scan a large project file for unusual HTTP responses and potential vulnerabilities. The examples identify authentication-related information disclosure, unexpected source-code leaks, malformed middleware responses, and servers running SMTP on port 443.

### Source excerpt

Security research involves a lot of failure. It's a perpetual balancing act between taking small steps with a predictable but boring outcome, and trying out wild concepts that are so crazy they might

## EF-Supported Teams: Research & Development Roundup

DevFeed: [EF-Supported Teams: Research & Development Roundup](<https://devfeed.tech/articles/ef-supported-teams-research-development-roundup-16973.md>)

Original publisher: [Read original article](<https://blog.ethereum.org/en/2021/08/12/ef-supported-teams-research-and-development-update-2021-pt-2>)

Author: Ethereum Foundation

Published: 2021-08-12T00:00:00Z

Content type: article

Language: en

Sources: [Ethereum Foundation Blog](<https://devfeed.tech/sources/ethereum-foundation-blog.md>)

Topics: [Development](<https://devfeed.tech/topics/development.md>), [Ethereum](<https://devfeed.tech/topics/ethereum.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [community](<https://devfeed.tech/tags/community.md>), [devcon](<https://devfeed.tech/tags/devcon.md>), [development](<https://devfeed.tech/tags/development.md>), [ethereum](<https://devfeed.tech/tags/ethereum.md>), [network](<https://devfeed.tech/tags/network.md>), [organizational](<https://devfeed.tech/tags/organizational.md>), [research-development](<https://devfeed.tech/tags/research-development.md>), [security-research](<https://devfeed.tech/tags/security-research.md>), [sharding](<https://devfeed.tech/tags/sharding.md>), [stateless](<https://devfeed.tech/tags/stateless.md>)

### AI overview

This roundup reports on progress from EF-supported Ethereum teams, including community grants, research into statelessness, custody proofs, sharding, scaling and security, and ethereum.org roadmap work. It also describes Ethereum network activity around the London update, Altair and the Merge.

### Source excerpt

Welcome to London! This is an exciting time for the Ethereum ecosystem, and the pace will only pick up further as we approach Altair and the Merge in the months ahead. The Beacon Chain now has 6.5+ million Ether staked, and 200K+ active validators online across five clients, and...

## Defeating Android Certificate Pinning with Frida

DevFeed: [Defeating Android Certificate Pinning with Frida](<https://devfeed.tech/articles/defeating-android-certificate-pinning-with-frida-19060.md>)

Original publisher: [Read original article](<https://httptoolkit.com/blog/frida-certificate-pinning/>)

Author: HTTP Toolkit; Tim Perry

Published: 2021-07-06T13:30:00Z

Content type: tutorial

Language: en

Sources: [HTTP Toolkit](<https://devfeed.tech/sources/http-toolkit.md>)

Topics: [Android](<https://devfeed.tech/topics/android.md>), [interception](<https://devfeed.tech/topics/interception.md>), [SSL](<https://devfeed.tech/topics/ssl.md>), [debug](<https://devfeed.tech/topics/debug.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [android](<https://devfeed.tech/tags/android.md>), [certificates](<https://devfeed.tech/tags/certificates.md>), [debugging](<https://devfeed.tech/tags/debugging.md>), [frida](<https://devfeed.tech/tags/frida.md>), [http](<https://devfeed.tech/tags/http.md>), [interception](<https://devfeed.tech/tags/interception.md>), [security](<https://devfeed.tech/tags/security.md>), [security-research](<https://devfeed.tech/tags/security-research.md>), [tls](<https://devfeed.tech/tags/tls.md>)

### AI overview

This tutorial explains Android certificate pinning, why it prevents HTTPS interception, and how Frida can be used to remove SSL pinning so researchers, developers, and privacy advocates can inspect an app's traffic.

### Source excerpt

Some Android apps go to astounding lengths to ensure that even the owner of a device can never see the content of the app's HTTPS requests. This is problematic for security research, privacy analysis and debugging, and for control over your own device in general. It's not a purely theoretical problem either - protections like this attempt to directly block HTTPS inspection tools like HTTP Toolkit, which allow you to automatically intercept HTTPS from Android devices for inspection, testing & mocking, like so: This depends on the target application(s) trusting the debugging proxy's certificate for HTTPS traffic. These HTTP interception and mocking techniques are super useful for testing and understanding most apps, but they have issues with the small set of hyper-vigilant apps that add extra protections aiming to lock down their HTTPS traffic and block this kind of inspection. In the end, this is your Android device, and whether you're a security researcher checking for vulnerabilities, a developer trying to understand how an app uses its API, or a privacy advocate documenting what data an app is sharing, you should be able to see the messages that the apps you use transmit and receive on your own phone. Protections like certificate pinning make this difficult. Let's talk about how you can fight back, by using Frida to remove SSL pinning, and expose the real traffic that any app is sending. What's certificate pinning? By default, when an Android app makes an HTTPS connection, it makes sure that it's talking to a trusted server by comparing the issuer of the server's certificate to Android's built-in list of trusted system certificate authorities. 99% of apps stick with that default. You can't change the system certificate authorities on normal devices, so this list is fairly reliable and secure. You can change it though on rooted devices and most emulators, so it's quite possible to intercept and inspect HTTPS traffic from these apps by using a debugging proxy for HT

## Security Audit Results for Teleport for 2021

DevFeed: [Security Audit Results for Teleport for 2021](<https://devfeed.tech/articles/security-audit-results-for-teleport-for-2021-29836.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/security-audit-2021/>)

Author: info@goteleport.com (Russell Jones)

Published: 2021-04-08T00:00:00Z

Content type: article

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [audit](<https://devfeed.tech/topics/audit.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Release notes](<https://devfeed.tech/topics/release-notes.md>)

Tags: [analysis](<https://devfeed.tech/tags/analysis.md>), [audit](<https://devfeed.tech/tags/audit.md>), [project](<https://devfeed.tech/tags/project.md>), [report](<https://devfeed.tech/tags/report.md>), [research](<https://devfeed.tech/tags/research.md>), [security](<https://devfeed.tech/tags/security.md>), [security-research](<https://devfeed.tech/tags/security-research.md>), [third-party](<https://devfeed.tech/tags/third-party.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Teleport reports the results of its 2021 independent security audit by Doyensec. The reassessment confirmed that all issues with direct security impact had been addressed, while four lower-impact or informational issues remained as accepted risks.

### Source excerpt

Results and independent analysis from a third party on the Teleport project. April 2021.

## Amicus Brief on CFAA

DevFeed: [Amicus Brief on CFAA](<https://devfeed.tech/articles/amicus-brief-on-cfaa-36669.md>)

Original publisher: [Read original article](<https://shostack.org/blog/amicus-brief-on-cfaa/>)

Author: Adam

Published: 2020-07-13T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>)

Tags: [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [law](<https://devfeed.tech/tags/law.md>), [research](<https://devfeed.tech/tags/research.md>), [security](<https://devfeed.tech/tags/security.md>), [security-research](<https://devfeed.tech/tags/security-research.md>), [us](<https://devfeed.tech/tags/us.md>)

### AI overview

The author says they signed an amicus brief filed by the Electronic Frontier Foundation in the Van Buren case. The brief urges the U.S. Supreme Court to limit the scope of the Computer Fraud and Abuse Act and clarify that violating terms of service when accessing computers does not itself violate the law.

### Source excerpt

I recently signed onto the amicus brief on the Van Buren/Computer Fraud and Abuse Act filed by the Electronic Frontier Foundation.

## How to Create a Malware Detection System With Machine Learning

DevFeed: [How to Create a Malware Detection System With Machine Learning](<https://devfeed.tech/articles/how-to-create-a-malware-detection-system-with-machine-learning-41262.md>)

Original publisher: [Read original article](<https://www.evilsocket.net/2019/05/22/How-to-create-a-Malware-detection-system-with-Machine-Learning/>)

Author: Simone Margaritelli

Published: 2019-05-22T21:59:13Z

Content type: tutorial

Language: en

Sources: [evilsocket](<https://devfeed.tech/sources/evilsocket.md>)

Topics: [Malware](<https://devfeed.tech/topics/malware.md>), [Machine Learning & Artificial Intelligence](<https://devfeed.tech/topics/machine-learning-artificial-intelligence.md>), [Neural Network](<https://devfeed.tech/topics/neural-network.md>), [Windows](<https://devfeed.tech/topics/windows.md>), [Code](<https://devfeed.tech/topics/code.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [antivirus](<https://devfeed.tech/tags/antivirus.md>), [binary-analysis](<https://devfeed.tech/tags/binary-analysis.md>), [classification](<https://devfeed.tech/tags/classification.md>), [computer-virus](<https://devfeed.tech/tags/computer-virus.md>), [cuda](<https://devfeed.tech/tags/cuda.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [deep-learning](<https://devfeed.tech/tags/deep-learning.md>), [deep-neural-networks](<https://devfeed.tech/tags/deep-neural-networks.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [dnn](<https://devfeed.tech/tags/dnn.md>), [ergo](<https://devfeed.tech/tags/ergo.md>), [feature-engineering](<https://devfeed.tech/tags/feature-engineering.md>), [features](<https://devfeed.tech/tags/features.md>), [gpu](<https://devfeed.tech/tags/gpu.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [keras](<https://devfeed.tech/tags/keras.md>), [machine-learning](<https://devfeed.tech/tags/machine-learning.md>), [malware](<https://devfeed.tech/tags/malware.md>), [malware-detection](<https://devfeed.tech/tags/malware-detection.md>), [neural-network](<https://devfeed.tech/tags/neural-network.md>), [neural-networks](<https://devfeed.tech/tags/neural-networks.md>), [nvidia](<https://devfeed.tech/tags/nvidia.md>), [portable-executable](<https://devfeed.tech/tags/portable-executable.md>), [security-research](<https://devfeed.tech/tags/security-research.md>), [tensorflow](<https://devfeed.tech/tags/tensorflow.md>), [tf](<https://devfeed.tech/tags/tf.md>), [windows-pe](<https://devfeed.tech/tags/windows-pe.md>)

### AI overview

A practical tutorial on using machine learning and artificial neural networks to detect Windows malware without relying on an explicit signatures database. It uses malware detection as an example for the ergo project, which automates parts of model creation, data encoding, GPU training, benchmarking, and deployment.

### Source excerpt

In this post we'll talk about two topics I love and that have been central elements of my (private) research for the last ~7 years: machi

## Security Engineering: Computers versus Bridges

DevFeed: [Security Engineering: Computers versus Bridges](<https://devfeed.tech/articles/security-engineering-computers-versus-bridges-36969.md>)

Original publisher: [Read original article](<https://shostack.org/blog/security-engineering-computers-versus-bridges/>)

Author: Adam

Published: 2018-04-11T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>)

Tags: [discussion](<https://devfeed.tech/tags/discussion.md>), [security](<https://devfeed.tech/tags/security.md>), [security-engineering](<https://devfeed.tech/tags/security-engineering.md>), [security-research](<https://devfeed.tech/tags/security-research.md>)

### AI overview

This commentary compares security engineering with bridge engineering, arguing that public criticism, questioning, and investigation of failures are essential to improving designs and advancing the field.

### Source excerpt

[no description provided]

## Security Research and the Elusive Goal of Scientific Rigor

DevFeed: [Security Research and the Elusive Goal of Scientific Rigor](<https://devfeed.tech/articles/the-elusive-goal-of-security-as-a-scientific-pursuit-37003.md>)

Original publisher: [Read original article](<https://shostack.org/blog/the-elusive-goal-of-security-as-a-scientific-pursuit/>)

Author: Adam

Published: 2017-04-25T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>)

Tags: [exploration](<https://devfeed.tech/tags/exploration.md>), [insights](<https://devfeed.tech/tags/insights.md>), [philosophy](<https://devfeed.tech/tags/philosophy.md>), [research](<https://devfeed.tech/tags/research.md>), [review](<https://devfeed.tech/tags/review.md>), [science](<https://devfeed.tech/tags/science.md>), [security](<https://devfeed.tech/tags/security.md>), [security-research](<https://devfeed.tech/tags/security-research.md>)

### AI overview

The article discusses a forthcoming paper on the meaning and practice of making computer security research more scientific. It reports limited clarity and consensus about a Science of Security, and identifies underused scientific practices and recurring methodological errors in security research.

### Source excerpt

[no description provided]

## Open Source Security Bug Bounty

DevFeed: [Open Source Security Bug Bounty](<https://devfeed.tech/articles/open-source-security-bug-bounty-15791.md>)

Original publisher: [Read original article](<https://developer.squareup.com/blog/open-source-security-bug-bounty>)

Author: Square Engineering

Published: 2015-05-11T16:08:00Z

Content type: release

Language: en

Sources: [Square Corner Blog RSS Feed](<https://devfeed.tech/sources/square-corner-blog-rss-feed.md>)

Topics: [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Bug Bounty](<https://devfeed.tech/topics/bugbounty.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [bounty](<https://devfeed.tech/tags/bounty.md>), [bug-bounty](<https://devfeed.tech/tags/bug-bounty.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [open-source-software](<https://devfeed.tech/tags/open-source-software.md>), [security](<https://devfeed.tech/tags/security.md>), [security-research](<https://devfeed.tech/tags/security-research.md>)

### AI overview

Square announces a security bug bounty program for its open source software. The program invites reports of security flaws in projects with a BUG-BOUNTY.md file and directs researchers to a dedicated HackerOne page.

### Source excerpt

A new way to get paid for bug reports

## Square's Security Bug Bounty

DevFeed: [Square's Security Bug Bounty](<https://devfeed.tech/articles/square-s-security-bug-bounty-15891.md>)

Original publisher: [Read original article](<https://developer.squareup.com/blog/squares-security-bug-bounty>)

Author: Square Engineering

Published: 2014-08-06T16:07:00Z

Content type: release

Language: en

Sources: [Square Corner Blog RSS Feed](<https://devfeed.tech/sources/square-corner-blog-rss-feed.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Bug Bounty](<https://devfeed.tech/topics/bugbounty.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Web](<https://devfeed.tech/topics/web.md>)

Tags: [announce](<https://devfeed.tech/tags/announce.md>), [bounty](<https://devfeed.tech/tags/bounty.md>), [bug-bounty](<https://devfeed.tech/tags/bug-bounty.md>), [community](<https://devfeed.tech/tags/community.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [program](<https://devfeed.tech/tags/program.md>), [security](<https://devfeed.tech/tags/security.md>), [security-research](<https://devfeed.tech/tags/security-research.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [web](<https://devfeed.tech/tags/web.md>)

### AI overview

Square announces a security bug bounty program with HackerOne and invites security researchers to report bugs for payment.

### Source excerpt

Crowdsourcing vulnerability discovery