HN user

chillax

1,768 karma
Posts147
Comments99
View on HN
blog.calif.io 1mo ago

Squidbleed (CVE-2026-47729) Heartbleeds ancient cousin, hiding in Squid since 97

chillax
3pts0
blog.jetbrains.com 1mo ago

Mellum2 Goes Open Source: A Fast Model for AI Workflows

chillax
7pts0
www.crowdstrike.com 1mo ago

Disrupting Glassworm: Inside CrowdStrike's Takedown of a Dev-Targeting Botnet

chillax
4pts0
github.com 2mo ago

Catch hallucinated, typosquatted, non-canonical dependencies before production

chillax
2pts0
www.resilientcyber.io 3mo ago

Vulnpocalypse: AI, Open Source, and the Race to Remediate

chillax
1pts0
blog.gitguardian.com 3mo ago

The Team PCP Snowball Effect: A Quantitative Analysis

chillax
4pts0
www.vaines.org 3mo ago

The Comforting Lie of SHA Pinning

chillax
15pts5
github.com 5mo ago

Invisible Prompt Injection Through Markdown and HTML-Comments

chillax
2pts0
riversecurity.eu 5mo ago

Turning Cloudflare into an SSRF Engine,Reaching What You Were Never Meant to See

chillax
1pts0
hntrbrk.com 5mo ago

Ubiquiti: The U.S. Tech Enabling Russia's Drone War

chillax
25pts3
zkorman.com 6mo ago

AI's Bottleneck Isn't Models or Tools, It's Security

chillax
1pts1
react2shell.com 7mo ago

React2shell

chillax
2pts0
doublepulsar.com 8mo ago

CyberSlop – meet the new threat actor, MIT and Safe Security

chillax
3pts0
auditkit.io 9mo ago

AuditKit – Multi-framework compliance scanner

chillax
1pts0
www.reuters.com 9mo ago

AMD signs AI chip-supply deal with OpenAI, gives it option to take a 10% stake

chillax
442pts370
arxiv.org 9mo ago

Security Degradation in Iterative AI Code Generation

chillax
1pts0
openjdk.org 10mo ago

JEP 500: Prepare to Make Final Mean Final

chillax
3pts0
martinfowler.com 10mo ago

Conversation: LLMs and Building Abstractions

chillax
1pts0
www.binarysecurity.no 11mo ago

Azure's Weakest Link – Full Cross-Tenant Compromise

chillax
1pts0
redmonk.com 11mo ago

The Great SSL Certificate Panic

chillax
22pts11
embracethered.com 11mo ago

Amazon Q Developer: Secrets Leaked via DNS and Prompt Injection

chillax
3pts0
ipv4.games 11mo ago

Welcome to the IPv4 Games

chillax
55pts29
meetingco.st 11mo ago

Meetingco.st – How much does that meeting cost?

chillax
2pts0
github.com 1y ago

WAF Detector – For Detecting and Testing Web Application Firewalls (WAFs), CDNs

chillax
3pts0
baxbench.com 1y ago

BaxBench: Can LLMs Generate Secure and Correct Back Ends?

chillax
2pts1
www.legitsecurity.com 1y ago

Remote Prompt Injection in Gitlab Duo Leads to Source Code Theft

chillax
214pts54
www.pillar.security 1y ago

GitHub Copilot and Cursor: How Hackers Can Weaponize Code Agents

chillax
1pts0
www.binarysecurity.no 1y ago

Azure's Weakest Link? How API Connections Spill Secrets

chillax
3pts0
labs.watchtowr.com 1y ago

8M Requests Later,We Made the SolarWinds Supply Chain Attack Look Amateur

chillax
1pts0
portswigger.net 1y ago

Top web hacking techniques of 2024

chillax
3pts0

Here is how OWASP define it:

Non-human identities (NHIs) are used to provide authorization to software entities such as applications, APIs, bots, and automated systems to access secured resources. Unlike human identities, NHIs are not controlled or directly owned by a human. Their identity object and authentication often work differently to human, and common human user security measures do not apply to them.

https://owasp.org/www-project-non-human-identities-top-10/20...

"Speaking at Time’s 100 Summit in New York City, the 76-year-old film-maker expressed regret over taking out guns from a later release of his 1982 sci-fi blockbuster ET: The Extra Terrestrial. In the 20th anniversary edition, agents saw their firearms replaced with walkie-talkies.

“That was a mistake,” he said on stage. “I never should have done that. ET is a product of its era. No film should be revised based on the lenses we now are, either voluntarily, or being forced to peer through.”"

In the same terrain: After Schrems II we're looking to migrate of Sendgrid in favor of a european alternative (we're based in Europe ourselves).

Can anyone recommend an european smtp/api provider, preferably also with a inbound mail api? So far we've looked into Mailjet, but have been let down by their support on a technical matter with their inbound mail service.