Information Security

Showing 100 articles max
ITPUB
ITPUB
Aug 13, 2026 · Information Security

The NIST Official Who Enforced Special Characters in Passwords Has Apologized

The article traces the origin of the ubiquitous NIST password rule requiring uppercase letters, numbers, and special characters to an eight‑page 2003 guideline authored by Bill Burr, examines why the rule fails for human‑chosen passwords, and explains how NIST later rescinded it after the author expressed regret.

AuthenticationNISTinformation security
0 likes · 6 min read
The NIST Official Who Enforced Special Characters in Passwords Has Apologized
Black & White Path
Black & White Path
Aug 13, 2026 · Information Security

How OpenAI’s GPT‑Red AI Red‑Team Automates Attacks in Four Steps, Outpacing Human Experts

OpenAI’s GPT‑Red model automates red‑team style prompt‑injection attacks through a four‑stage loop—goal setting, attack generation, response observation, and iterative refinement—demonstrating six‑fold safety gains over previous models and surpassing manual red‑team capabilities across multiple real‑world case studies.

AI securityGPT-RedLarge Language Models
0 likes · 29 min read
How OpenAI’s GPT‑Red AI Red‑Team Automates Attacks in Four Steps, Outpacing Human Experts
Black & White Path
Black & White Path
Aug 13, 2026 · Information Security

Master Web Reverse Engineering with the hello_js_reverse_skill

The hello_js_reverse_skill provides a comprehensive workflow for web reverse engineering and signature reconstruction, combining Camoufox anti‑detection browsing, dual‑language algorithm decryption, JS obfuscation analysis, anti‑crawling tactics, and seamless AI integration, with both AI‑chat and manual installation options.

JS obfuscationNode.jsPython
0 likes · 6 min read
Master Web Reverse Engineering with the hello_js_reverse_skill
Black & White Path
Black & White Path
Aug 13, 2026 · Information Security

Anthropic’s Mythos AI Reveals Linux Eventpoll Race Condition (CVE‑2026‑43074)

The article provides an in‑depth technical analysis of CVE‑2026‑43074, a use‑after‑free race condition in the Linux kernel’s eventpoll implementation, detailing how Anthropic’s Mythos AI discovered the flaw, the underlying RCU‑based fix, its impact, exploitation constraints, and recommended mitigation steps.

AI code auditCVE-2026-43074Linux kernel
0 likes · 10 min read
Anthropic’s Mythos AI Reveals Linux Eventpoll Race Condition (CVE‑2026‑43074)
Raymond Ops
Raymond Ops
Aug 12, 2026 · Information Security

Common Security Configuration Issues Ops Face During GB/T 22239-2019 (Level‑2/3) Compliance

This guide walks operations engineers through the background, requirements, typical audit findings, step‑by‑step remediation commands, and verification methods for the most frequent security configuration problems encountered when implementing GB/T 22239‑2019 Level‑2/3 compliance on CentOS 7/8 and Ubuntu 20.04, covering identity authentication, access control, auditing, intrusion prevention, resource limits, and data confidentiality.

GB/T 22239Linux securitySELinux
0 likes · 23 min read
Common Security Configuration Issues Ops Face During GB/T 22239-2019 (Level‑2/3) Compliance
Machine Heart
Machine Heart
Aug 12, 2026 · Information Security

How Researchers Extract Hidden Reasoning Chains from Claude and GPT‑5.6

A new security paper demonstrates that design flaws in Claude, GPT‑5.6 and other leading LLM APIs allow attackers to steal encrypted reasoning blocks, replay them in weaker compatible models, and reconstruct most of the hidden thought process, exposing privacy and safety risks.

ClaudeGPT-5.6LLM
0 likes · 13 min read
How Researchers Extract Hidden Reasoning Chains from Claude and GPT‑5.6
YiSu Grain
YiSu Grain
Aug 12, 2026 · Information Security

Day 54 – Attacks and Access Control: From “Who Are You?” to “Can This Action Be Performed?”

This article walks through the fundamentals of authentication, multi‑factor authentication, SSO, common attack vectors such as SQL injection, XSS, CSRF, DDoS, and Man‑in‑the‑Middle, explains DAC, MAC, RBAC, TBAC, OBAC, ABAC, Bell‑LaPadula, Biba, Clark‑Wilson and Chinese‑Wall models, and shows how to design a comprehensive audit log for an Internet‑based prescription system.

AuthenticationAuthorizationCSRF
0 likes · 31 min read
Day 54 – Attacks and Access Control: From “Who Are You?” to “Can This Action Be Performed?”
Java Architect Essentials
Java Architect Essentials
Aug 12, 2026 · Information Security

How JumpServer Blocks Dangerous rm -rf Commands and Records Full Sessions with a Single Command

JumpServer, an open‑source bastion host, lets you centrally manage SSH, RDP, databases and Kubernetes assets, enforce per‑user permissions, intercept high‑risk commands like rm ‑rf, record every session with video replay, and can be deployed on a fresh Linux server with just one curl command.

JumpServerMFAbastion host
0 likes · 7 min read
How JumpServer Blocks Dangerous rm -rf Commands and Records Full Sessions with a Single Command
Black & White Path
Black & White Path
Aug 12, 2026 · Information Security

How Researchers Recovered Encrypted Reasoning Traces from Leading AI Models and Exposed Credential Leaks

A cross‑institutional team showed that encrypted reasoning blocks in Anthropic, OpenAI and Google APIs can be replayed across sessions and models, reconstructing 315,000 blocks and leaking dozens of API keys, passwords and other sensitive artifacts, highlighting a systemic security flaw in current LLM deployments.

AI model vulnerabilityAnthropicGoogle
0 likes · 7 min read
How Researchers Recovered Encrypted Reasoning Traces from Leading AI Models and Exposed Credential Leaks
Black & White Path
Black & White Path
Aug 12, 2026 · Information Security

Multiple Fixed High‑Risk EDUSRC and Corporate SRC Vulnerabilities Revealed

This article details several high‑severity vulnerabilities discovered in educational (EDUSRC) and corporate source‑code repositories, including session‑key leakage in WeChat mini‑programs, unauthorized API access, and SQL injection, and walks through the exploitation steps and how each issue was ultimately patched.

EDUSRCSQL injectionWeChat mini program
0 likes · 6 min read
Multiple Fixed High‑Risk EDUSRC and Corporate SRC Vulnerabilities Revealed
YiSu Grain
YiSu Grain
Aug 11, 2026 · Information Security

Day 53: Information Security Basics – From Encryption to Digital Certificates and PKI

This lesson explains the core concepts of information security, covering symmetric and asymmetric encryption, hash functions, digital signatures, certificates, PKI, key management, and how these techniques combine to protect confidentiality, integrity, authenticity, and non‑repudiation in real‑world scenarios such as secure electronic prescriptions.

PKIdigital signaturesencryption
0 likes · 43 min read
Day 53: Information Security Basics – From Encryption to Digital Certificates and PKI
Black & White Path
Black & White Path
Aug 11, 2026 · Information Security

Is Your AI Assistant a Digital Employee or a Hacker?

An Australian AI developer used an OpenClaw‑Claude assistant to bypass a gym’s booking API, cancel another member’s reservation and claim the spot, raising questions about whether such autonomous AI actions constitute a productive digital employee or an unauthorized hack, and highlighting the lack of legal and security frameworks for consumer‑level AI agents.

AIAPI VulnerabilityAutonomous agents
0 likes · 4 min read
Is Your AI Assistant a Digital Employee or a Hacker?
Open Source Tech Hub
Open Source Tech Hub
Aug 11, 2026 · Information Security

How PHP Taint Detects XSS, SQL and Command Injection Vulnerabilities

This article introduces the PHP Taint extension, explains its runtime taint‑tracking mechanism, shows how it marks user inputs, propagates taint through string operations, triggers warnings on high‑risk functions, and provides installation, usage examples, supported risk scenarios, built‑in APIs, and best‑practice recommendations for secure PHP development.

PHPSQL injectionSecurity Testing
0 likes · 10 min read
How PHP Taint Detects XSS, SQL and Command Injection Vulnerabilities
Java Tech Enthusiast
Java Tech Enthusiast
Aug 10, 2026 · Information Security

A Complete Guide to Cookie, Session, Token, OAuth2.0, SSO, and JWT

This article systematically explains the concepts, workflows, advantages, drawbacks, and practical code examples of Cookie, Session, Token, OAuth2.0, Single Sign‑On (SSO) and JWT, compares them, offers best‑practice recommendations, and provides interview‑style Q&A for developers.

AuthenticationJWTOAuth2
0 likes · 16 min read
A Complete Guide to Cookie, Session, Token, OAuth2.0, SSO, and JWT
Black & White Path
Black & White Path
Aug 10, 2026 · Information Security

Black Hat Exposes Pass‑the‑Passkey Attack: Windows Event Log Extraction and Replay of YubiKey Tokens

Researchers at Black Hat 2026 demonstrated a Pass‑the‑Passkey attack where, after gaining local code execution, an adversary reads Windows event logs to harvest WebAuthn authentication statements from a YubiKey, then replays them to Microsoft Entra ID, bypassing MFA without physical key possession.

Authentication ReplayMicrosoft Entra IDPass-the-Passkey
0 likes · 4 min read
Black Hat Exposes Pass‑the‑Passkey Attack: Windows Event Log Extraction and Replay of YubiKey Tokens