Hacker Newsnew | past | comments | ask | show | jobs | submit | fromlogin
Subverting code integrity checks to locally backdoor Signal, 1Password and more (trailofbits.com)
2 points by elashri 1 day ago | past | discuss
Subverting code integrity checks to locally backdoor Signal, 1Password, Slack (trailofbits.com)
9 points by tatersolid 1 day ago | past | discuss
Weaponizing image scaling against production AI systems (trailofbits.com)
494 points by tatersolid 16 days ago | past | 131 comments
Marshal madness: A brief history of Ruby deserialization exploits (trailofbits.com)
25 points by pentestercrab 17 days ago | past | 4 comments
Hijacking multi-agent systems in your PajaMAS (trailofbits.com)
7 points by Qwuke 18 days ago | past | 1 comment
MCP servers can attack you before you ever use them (trailofbits.com)
2 points by gtirloni 23 days ago | past
Trail of Bits' Buttercup wins 2nd place in AIxCC Challenge (trailofbits.com)
2 points by wslh 26 days ago | past
Buttercup is now open-source (trailofbits.com)
14 points by wslh 26 days ago | past
Buttercup is now open-source (trailofbits.com)
1 point by wrayjustin 27 days ago | past
Prompt injection engineering for attackers: Exploiting GitHub Copilot (trailofbits.com)
11 points by agentictime 27 days ago | past | 1 comment
Buttercup is now open-source (trailofbits.com)
15 points by wglb 28 days ago | past
GitHub Copilot Agent prompt injection via Issues (trailofbits.com)
2 points by feliperalmeida 29 days ago | past
Memory corruption in Nvidia Triton (as a new hire) (trailofbits.com)
2 points by ingve 32 days ago | past
Hijacking multi-agent systems in your PajaMAS (trailofbits.com)
2 points by frabert 37 days ago | past | 1 comment
We built the security layer MCP always needed (trailofbits.com)
3 points by wslh 39 days ago | past
Exploiting zero days in abandoned hardware (trailofbits.com)
113 points by ingve 43 days ago | past | 35 comments
Detecting code copying at scale with Vendetect (trailofbits.com)
2 points by gpi 46 days ago | past
Detecting code copying at scale with Vendetect (trailofbits.com)
2 points by ingve 47 days ago | past
Investigate Your Dependencies with Deptective (trailofbits.com)
2 points by ingve 60 days ago | past
Buckle up, Buttercup, AIxCC's scored round is underway (trailofbits.com)
1 point by wslh 65 days ago | past
Unexpected security footguns in Go's parsers (trailofbits.com)
234 points by ingve 80 days ago | past | 132 comments
Insecure credential storage plagues MCP (trailofbits.com)
4 points by mooreds 86 days ago | past
The Custodial Stablecoin Rekt Test (trailofbits.com)
2 points by wslh 3 months ago | past
The cryptography behind passkeys (trailofbits.com)
276 points by tatersolid 3 months ago | past | 263 comments
Making PyPI's test suite faster (trailofbits.com)
125 points by rbanffy 4 months ago | past | 39 comments
Making PyPI's test suite 81% faster (trailofbits.com)
8 points by zdw 4 months ago | past
Insecure credential storage plagues MCP (trailofbits.com)
2 points by wslh 4 months ago | past
Making PyPI's test suite 81% faster (trailofbits.com)
11 points by woodruffw 4 months ago | past | 2 comments
Deceiving users with ANSI terminal codes in MCP (trailofbits.com)
3 points by HypnoticOcelot 4 months ago | past | 1 comment
MCP servers can steal your conversation history (trailofbits.com)
1 point by ingve 4 months ago | past

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: