Hacker Newsnew | past | comments | ask | show | jobs | submit | fromlogin
Subverting code integrity checks to locally backdoor Signal, 1Password and more (trailofbits.com)
2 points by elashri 17 days ago | past
Subverting code integrity checks to locally backdoor Signal, 1Password, Slack (trailofbits.com)
9 points by tatersolid 18 days ago | past
Weaponizing image scaling against production AI systems (trailofbits.com)
494 points by tatersolid 32 days ago | past | 131 comments
Marshal madness: A brief history of Ruby deserialization exploits (trailofbits.com)
25 points by pentestercrab 33 days ago | past | 4 comments
Hijacking multi-agent systems in your PajaMAS (trailofbits.com)
7 points by Qwuke 34 days ago | past | 1 comment
MCP servers can attack you before you ever use them (trailofbits.com)
2 points by gtirloni 40 days ago | past
Trail of Bits' Buttercup wins 2nd place in AIxCC Challenge (trailofbits.com)
2 points by wslh 42 days ago | past
Buttercup is now open-source (trailofbits.com)
14 points by wslh 43 days ago | past
Buttercup is now open-source (trailofbits.com)
1 point by wrayjustin 43 days ago | past
Prompt injection engineering for attackers: Exploiting GitHub Copilot (trailofbits.com)
11 points by agentictime 44 days ago | past | 1 comment
Buttercup is now open-source (trailofbits.com)
15 points by wglb 45 days ago | past
GitHub Copilot Agent prompt injection via Issues (trailofbits.com)
2 points by feliperalmeida 45 days ago | past
Memory corruption in Nvidia Triton (as a new hire) (trailofbits.com)
2 points by ingve 48 days ago | past
Hijacking multi-agent systems in your PajaMAS (trailofbits.com)
2 points by frabert 53 days ago | past | 1 comment
We built the security layer MCP always needed (trailofbits.com)
3 points by wslh 56 days ago | past
Exploiting zero days in abandoned hardware (trailofbits.com)
113 points by ingve 59 days ago | past | 35 comments
Detecting code copying at scale with Vendetect (trailofbits.com)
2 points by gpi 62 days ago | past
Detecting code copying at scale with Vendetect (trailofbits.com)
2 points by ingve 63 days ago | past
Investigate Your Dependencies with Deptective (trailofbits.com)
2 points by ingve 76 days ago | past
Buckle up, Buttercup, AIxCC's scored round is underway (trailofbits.com)
1 point by wslh 82 days ago | past
Unexpected security footguns in Go's parsers (trailofbits.com)
234 points by ingve 3 months ago | past | 132 comments
Insecure credential storage plagues MCP (trailofbits.com)
4 points by mooreds 3 months ago | past
The Custodial Stablecoin Rekt Test (trailofbits.com)
2 points by wslh 3 months ago | past
The cryptography behind passkeys (trailofbits.com)
276 points by tatersolid 4 months ago | past | 263 comments
Making PyPI's test suite faster (trailofbits.com)
125 points by rbanffy 4 months ago | past | 39 comments
Making PyPI's test suite 81% faster (trailofbits.com)
8 points by zdw 4 months ago | past
Insecure credential storage plagues MCP (trailofbits.com)
2 points by wslh 4 months ago | past
Making PyPI's test suite 81% faster (trailofbits.com)
11 points by woodruffw 4 months ago | past | 2 comments
Deceiving users with ANSI terminal codes in MCP (trailofbits.com)
3 points by HypnoticOcelot 4 months ago | past | 1 comment
MCP servers can steal your conversation history (trailofbits.com)
1 point by ingve 5 months ago | past

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: