Generated 15/06/2026, 09:18. Pipeline: Europe/Belgrade. Regular sources favor exploit, blog, red-team, and attack-path content. CVE items only stay with exploit signal.
Total items15
Regular sources4
Tweets / X11
Threshold0.62
You can save this report in your browser with the favorite button. If you need a shared favorite list, use the CLI helper.
Tweets / X
11 items
Jhaddix @Jhaddix
12 Jun, 17:02 · core
0.58
We've all been there. A major breach drops and you're piecing together the story from a dozen different sources. The GitHub/TeamPCP incident is a perfect example. ~3,800 internal repos exfiltrated, LAPSUS$ involved as the monetization arm, a supply chain campaign that had been
Sucky outcome but not untrue. Muti-turn model forcing, several evasions, context overload, and a verbatim jailbreak by BT6 and @elder_plinius were all going around. They all illustrated the ability of the model to do simple exploitation, but every demonstration I saw to do
Unit 42 is tracking the active targeting of Oracle PeopleSoft servers by Bling Libra (aka #ShinyHunters). Our analysis reveals suspected exploitation of RCE flaw CVE-2026-35273 and primary targeting of the education sec…
This is a tricky question and, in a bit of irony, there is a kind of like ... an unspoken ... or poorly documented philosophy of malware development. You kind of learn tricks of the trade as you write malware and witness malware campaigns operating in the wild. tl;dr idk it what
I’m once again here to tell you that *most* bug bounty platforms will or have used your hunting data in AI endeavors. bug bounty as an enterprise strategy is much lower margin than AI security. Or they will use it for auto triage. Which then they will conveniently forget
Very happy the Google phishing live demo was a success after the internet connection suddenly stopped working briefly on stage. Demo gods today tried to play some tricks. #Evilginx is back this year at #x33fcon, @mrgretzky is presenting "Downgrading #FIDO #MFA With #AI Slop" - #r
And there we go, digital id… fuck sake!! NEW: The UK social media ban for under-16s will be enforced through facial recognition, digital IDs, credit cards, open banking, passports, mobile provider checks or email age estimation
Matthew Nguyen starting the party for ContinuumCon Day 3, walking us through using Malcat (), FakeNet, and more for some sweet malware analysis! https:// continuumcon.com Workshop Spotlight #8 "How to Analyze Malware" by Matthew Nguyen Description A practical introduction to malw
Week in review: Exploited Check Point VPN zero-day, Oracle PeopleSoft servers under attack
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: DockSec: Open-source AI-powered Docker security scanner DockSec is an O…
1.00exploit · 14 Jun, 00:35seclists.org
Re: Proposal: Add separate oss-security-vulnerability-reports mailing list (for AI vulnpocalypse)
Posted by Solar Designer on Jun 13 Hi David, Thank you for bringing this up. I do indeed see the problem, but I don't like the proposal. Also, for now the increased volu…
1.00general · 12 Jun, 11:50thehackernews.comRCE
LangGraph Flaw Chain Exposes Self-Hosted AI Agents to Remote Code Execution
Cybersecurity researchers have disclosed details of three now-patched security flaws impacting LangGraph, including a critical vulnerability chain that could result in r…
1.00general · 12 Jun, 07:40helpnetsecurity.com
ZeroFox releases AI Analytics to bring answers directly to security teams
ZeroFox launched ZeroFox AI Analytics, a new platform capability that gives security teams real-time visibility into the signals, patterns, and trends shaping their exte…