Generated 02/06/2026, 09:16. Pipeline: Europe/Belgrade. Regular sources favor exploit, blog, red-team, and attack-path content. CVE items only stay with exploit signal.
Total items15
Regular sources4
Tweets / X11
Threshold0.62
You can save this report in your browser with the favorite button. If you need a shared favorite list, use the CLI helper.
Tweets / X
11 items
mrgretzky @mrgretzky
01 Jun, 16:47 · core
0.56
I wanted to address the speculation about the recently introduced Device Bound Session Credentials (DBSC) security feature in Google Chrome. Does it help increase the security of session cookies against infostealer malware and MFA phishing? The feature has been available and Goog
I've published an article on how an attacker could break into the Claude Code supply chain! We've published a new blog post by RyotaK @ryotkak. He discovered a vulnerability that allows attackers to bypass the permission controls of Claude Code GitHub Actions via a GitHub issue,
During an assessment, our team discovered that StrongDM auth state files containing JWTs & key material could be reused across hosts to obtain authenticated sessions & access infrastructure resources (CVE-2026-4387). Re…
I'm excited to be able to finally publish the public disclosure for CVE-2026-4387. Check out my blog on discovering the reuse of the state.kv file to get authenticated sessions with StrongDM (now fixed).
Attending #CiscoLive in Las Vegas? Stop by booth 2206 and connect with our team. We'd love to discuss your identity attack path management questions and show you how BloodHound Enterprise helps organizations uncover and reduce hidden risk.
Tomorrow we're live at 1 p.m. ET / 10 a.m. PT for our latest episode of SecOps Weekly! Phil Hagen and Chris Brook are hopping on to chat about the latest security trends and answer audience questions from our mailbag. Join us live to hear their take and learn what you and your
Don't miss "Signal to Enforcement: A Coordinated Security Walkthrough" featuring @jaredcatkinson at 4:30 PM. Follow a real-world attacker path across identity, SaaS, devices, and networks, and see how integrated security architectures enable coordinated response and enforcement.
Your “agentic coworker” is sending suspicious messages via Microsoft Teams. It’s going to need to have a chat with the agentic HR department. Read Part 2 of our series on investigating suspicious AI workflows in Entra ID: https:// redcanary.com/blog/threat-de tection/entra-id-ai-
The problem with agentic security workflows isn't access to data. It's making that data callable from the agent. The Sysdig MCP server on AWS Marketplace closes that gap, inside Amazon Bedrock AgentCore. Read the blog: https:// okt.to/uVP2Fe #CloudSecurity
As I'm sure you've all seen by now, nerds have been exploiting Meta's AI agent goop to steal Instagram accounts. The Instagram AI agent for support could be convinced to reset the credentials to other users accounts by asking nicely and do a super gnarly kickflip on a
Windows Netlogon RCE exploited, domain controllers at risk (CVE-2026-41089)
CVE-2026-41089, a critical Windows Netlogon RCE flaw that allows remote code execution, is now actively exploited in the wild, the Centre for Cybersecurity Belgium (CCB)…
⚡ Weekly Recap: New Linux Flaw, PAN-OS Exploit, AI-Powered Attacks, OAuth Phishing and More
Monday hit like a cron job with anger issues. A busted auth path here, a repo-side faceplant there, some "patched-ish" thing already getting chewed on in the wild, and t…
1.00general · 01 Jun, 06:00helpnetsecurity.com
145 AI laws passed in 2025 and privacy teams aren’t catching a break
145 AI-related laws were enacted by state legislatures in 2025, and more than 1,000 additional bills were introduced or revised, according to DataGrail’s Privacy and AI …
0.89exploit · 01 Jun, 08:24seclists.orgResearch
CyberDanube Security Research 20260528-0 | Multiple Vulnerabilities in Multiple Vulnerabilities in Mennekes Amtron Series
Posted by Thomas Weber | CyberDanube via Fulldisclosure on May 31 CyberDanube Security Research 20260528-0 https://www.mennekes.at/ found|...