Generated 30/07/2026, 09:40. Pipeline: Europe/Belgrade. Regular sources favor exploit, blog, red-team, and attack-path content. CVE items only stay with exploit signal.
Total items15
Regular sources2
Tweets / X13
Threshold0.62
You can save this report in your browser with the favorite button. If you need a shared favorite list, use the CLI helper.
Tweets / X
13 items
mrgretzky @mrgretzky
29 Jul, 11:43 · core
0.50
Excited to be back as a @defcon mainstage speaker in Vegas for the 2nd year in a row! This year I'll reveal new techniques to get Microsoft to deliver any phishing email from official Microsoft addresses. Plus... interactive phishing pages rendered inside email clients!?
Who can actually assume that role? Who can reach your secrets, keys, or data? @hotnops explores how BloodHound Enterprise brings the attack path mindset to AWS to answer those questions.
On 7/27/26, #JetBrains published a security advisory for CVE-2026-63077, a critical vuln. affecting all versions of TeamCity On-Premises. Attackers who exploit the vulnerability can read stored credentials and compromise CI/CD pipeline integrity. More: https:// r-7.co/4h3tVFR
The AI didn't magically escape the network. It found the same exposed secrets, flat networks, overprivileged service accounts, and forgotten admin portals we've been documenting in pentest reports for the last decade. Apparently those findings only became urgent once the attacker
Cisco Talos Incident Response’s Q2 trends report is out. Author Lexi DiScola joins Amy to show you exactly how attackers are evolving and the practical steps you can take to stop them: https:// cs.co/6016BEatZw
just remember the AI hackbot training corpus wouldn't exist without the research and hacking community at cons like @BlackHatEvents & @defcon (and all other cons) keep researching, keep learning, keep hacking... it's gonna be ok.
We at @pdiscoveryio are looking to hire a cracked security researcher. priority on heavy CTF background & pure research experience over standard bug bounty work. need high agency, total ownership, zero hand-holding. looking for the absolute best in the game. DMs are open
Come and see @m4st3rspl1nt3r and I present "CRLF-Powered Desync Attacks: Beheading HTTP Streams" at @BlackHatEvents and @defcon next week! We cannot wait to share what we've found! In less than 2 weeks @t0xodile and I will present "CRLF-Powered Desync Attacks: Beheading HTTP Stre
Started tracking the new mini-articles I’m posting to socials on my blog at https:// blog.xpnsec.com/articles Hopefully helps to keep track of what was posted where
Compromise one node in a Windows Server Failover Cluster and you've compromised all of them. @unsigned_sh0rt dug into why: shared credentials, forged tickets, and a full attack chain to own the cluster. Check it out!
Hi I've uploaded another 150,000 malwares to the internet. I haven't pushed the update file yet, but the malware is there for you to download and enjoy. If you need anything please contact me secretary (homeless guy at the gas station) Cheers, Pic unrelated
Every cloud change creates a new security decision. This month’s Falcon Cloud Security release reduces operational effort so your team can move faster. IaC security in VS Code & IntelliJ Custom Rego Rules 1-click CIEM remediation Agentless Azure VM Scanning K8s
Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory
Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, that coul…
1.00general · 29 Jul, 10:58thehackernews.comPoC
Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass
Cybersecurity researchers have shared additional technical details about a recently patched critical security flaw impacting Check Point Security Management Server and M…