Generated 19/08/2026, 09:40. Pipeline: Europe/Belgrade. Regular sources favor exploit, blog, red-team, and attack-path content. CVE items only stay with exploit signal.
Total items15
Regular sources3
Tweets / X12
Threshold0.62
You can save this report in your browser with the favorite button. If you need a shared favorite list, use the CLI helper.
Tweets / X
12 items
Jhaddix @Jhaddix
18 Aug, 23:48 · core
0.62
Most AI Red Teaming or Pentesting courses teach you one or two agent exfiltration methods... In our next version of "Attacking AI" We'll be sharing exclusive tooling (Agent-Raider) with the students that allows you to create payloads for our proprietary ~80 exfiltration
H4x0r.DZ @h4x0r_dz · 18h securifera.com File Drop to RCE - CVE-2026-20217 I remember watching Simon Scannell's REcon 2023 talk, You Have Become the Very Thing You Swore to Destroy, and being deeply impressed by how he t…
OK that is pretty cool :D Our AI attacker autonomously made its way into @Snowflake's internal Jira, accessing sensitive data simply by opening a public GitHub issue with a crafted title. The flaw was introduced 5 days earlier by "Copilot Autofix powered by AI"
Love how they picked the next GitHub outage... well played Cursor :D Looking forward to trying this! Origin, our code hosting platform, is now live. It's fast, easy to use, and deeply integrated with Cursor. Get started by syncing your repos from GitHub.
Threat actor theHatman is selling corporate data allegedly exfiltrated from Microsoft Entra tenants. Unit 42 hasn't verified the specific intrusion vector, but we advise using mitigations appropriate to credential attacks, as outlined here: https:// bit.ly/3RWfERf
403 Access Bypass Tester - UnKover Built to find this and many more across our 33 cases testbed. Fewer false positives, cleaner results. https:// github.com/BruteLogic/unK over … Path Normalization 403 Bypass Nginx might fall for a mismatch in the location block. Blocked https://
Attention Ohio tech & cyber pros! Synack is proud to sponsor OptivCon Columbus on September 1st (8:00 AM - 4:30 PM) at the Hilton Columbus Downtown! Looking for a pentesting partner that scales with your attack surface? Reserve a time to meet:
62% of exploited vulnerabilities this quarter needed no click or interaction from the user at all - up 24% from Q1 alone. You can’t patch everything. So what do you fix first? Download Rapid7's latest Quarterly Threat Report for more: https:// r-7.co/3U3kixo
Chat, I've decided I'm going to continue working on vx-underground for the remainder of my life. I'm in my 30s. I'm 7.5 years deep. I work on my shitty website literally every single day, with the exception being major life events. After 7.5 years of malware nonstop, I am still
Most security teams only see what makes it into the final report. But the real signal often starts earlier. It starts in the paths explored, the assets questioned, and the context built before a finding is found. That is where recon becomes more than research; it becomes
Most security leaders know exactly what they spent on bug bounty programs last year. Far fewer can actually prove what was tested. Synack’s Dave Henderson breaks down how Managed Bug Bounty shifts security testing from an act of faith into measurable, auditable proof:
BloodHound is 10 To celebrate, creators @_wald0 , @CptJesus & @harmj0y joined for a special two-part #KnowYourAdversary. They reminisce on the first attack graphs and look ahead to what’s next for BloodHound. : https:// ghst.ly/4xT4WdA : https:// ghst.ly/4zIIeqj
Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets
Two critical vulnerabilities impacting MLflow, an open-source artificial intelligence (AI) platform, and FUXA, an open-source, web-based SCADA / HMI software built for o…
CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a critical flaw impacting Ray to its Known Exploited Vulnerabilities (KEV) catalog, citi…
One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025
A single piece of infrastructure has been pulling records out of Salesforce and ServiceNow customer portals across multiple industries for more than a year, according to…