Generated 29/07/2026, 09:49. Pipeline: Europe/Belgrade. Regular sources favor exploit, blog, red-team, and attack-path content. CVE items only stay with exploit signal.
Total items15
Regular sources7
Tweets / X8
Threshold0.62
You can save this report in your browser with the favorite button. If you need a shared favorite list, use the CLI helper.
Tweets / X
8 items
harmj0y @harmj0y
28 Jul, 14:18 · core
0.60
ESC1 is alive again. Low priv user to Domain Admin on a fully patched AD CS. Enforcement set to 2. The issued cert came back with NO szOID_NTDS_CA_SECURITY_EXT at all, over the CMC addExtensions path. MSRC: "Not a Vulnerability." Original research by @harmj0y and @tifkin_ .
On 7/22/26, #CheckPoint published a security advisory for CVE-2026-16232 - an authentication bypass vuln in SmartConsole, which admins use to manage Check Point policy & configuration. For our technical analysis, proof …
Your attack surface doesn't stop at AD. BloodHound Enterprise now supports AWS & Microsoft Entra Agent ID. We're also introducing BloodHound Hunter to bring attack path intel into AI workflows. Learn more https:// ghst.ly/4fZQN7W
Want to get more from BloodHound? Our BloodHound Basics course teaches you how to collect data, analyze attack paths, write Cypher queries, work with OpenGraph, and more through hands-on labs. Available now in Tradecraft Academy: https:// ghst.ly/4wBbZqE
An MCP server isn't just a wrapper around your REST API. AI agents explore before they act, so MCP tools should be designed around intent, not implementation. Kaleb Pomeroy explains why that distinction matters for security workflows. https:// ghst.ly/4x80M0X
Know every way to break a JWT. Every technique, every payload, tested and ready. Algorithm confusion, header field injection, claim manipulation, format attacks - including original research not documented in any public resource. https:// brutelogic.net/ebooks/broken- token/jwt …
A critical CVE... A predictable SSO ticket... An account takeover! So why isn't this being mass exploited? Our latest research on CVE-2026-11374 breaks down the attack path, why exploitability is limited, and what defenders should do next.
Finding a potential XSS is only the first step. Neo automatically : -> opens a real browser -> executes the payload -> confirms JavaScript execution -> captures the alert screenshot as evidence -> Introducing Neo Browser Computer Use -- an autonomous PoC collector. Finding XSS
vBulletin fixes critical pre-auth RCE flaw with public exploit
A critical vulnerability in the vBulletin forum software allows unauthenticated attackers to execute arbitrary PHP code through template rendering. [...]
1.00exploit · 28 Jul, 07:55seclists.orgTradecraft
[NotCVE-2026-0010] Barrier 2.4.0 for Windows Unauthenticated IPC Command Execution Allows Local Privilege Escalation to SYSTEM
Posted by advisories on Jul 27 ---------------------------------------------------------------------------- NotCVE Advisory - NotCVE-2026-0010 --------------------------…
A maximum-severity security flaw impacting on-premises versions of Arista VeloCloud Orchestrator (VCO) has come under active exploitation in the wild. The vulnerability,…
Hackers target US firms in FastJson RCE zero-day attacks
Hackers are actively exploiting a vulnerability in the FastJson open-source Java library, allowing remote code execution without user interaction or elevated privileges.…
Call of Duty Mobile scam uses fake free points giveaway to hijack players’ accounts
Call of Duty Mobile players should watch out for a phishing campaign disguised as a free Call of Duty Points giveaway, Malwarebytes researchers have warned. Victims are …
0.89exploit · 28 Jul, 07:48seclists.org
Re: Linux kernel: KVM: Merge branch 'kvm-chainsaw' into HEAD
Posted by Sam James on Jul 27 Reid Sutherland writes: Paolo has been a maintainer for a long time and in FOSS even longer than that. Big refactoring can introduce bugs b…
0.74critical · 28 Jul, 14:00cisa.govRCE
Siemens Desigo CC
View CSAF Summary OpenSSL has published a stack based buffer overflow vulnerability that allows a remote attacker to cause a denial of service (DoS) or potentially allow…