Generated 23/07/2026, 09:39. Pipeline: Europe/Belgrade. Regular sources favor exploit, blog, red-team, and attack-path content. CVE items only stay with exploit signal.
Total items15
Regular sources4
Tweets / X11
Threshold0.62
You can save this report in your browser with the favorite button. If you need a shared favorite list, use the CLI helper.
Tweets / X
11 items
SpecterOps @SpecterOps
22 Jul, 23:14 · core
0.60
There's still time to register for our Tradecraft Analysis training at #BHUSA! Save your spot today & join us to learn a practical approach and workflow for developing robust detection analytics or data driven evasion decisions. https:// ghst.ly/43eLw5s
Most hunters fail to test for SSTIs as finding them can feel difficult... However, knowing where to probe for injections and exploiting them can mean the difference between a dead end and an RCE! Our complete guide walks you through detection, engine fingerprinting, and
The #BloodHoundUnleashed Attack Path Championship is LIVE! Password: LeadThePack Complete the challenge before #BHUSA, then visit Kennel Club for bonus codes to boost your leaderboard score. Get started https:// unleashed.bloodhound.quest
One frontier model just completed a full autonomous malware investigation, running inside a hard no-network-egress boundary. @LabsSentinel built that boundary for a reason: autonomous agents can now find vulnerabilities to break out and exploit them in the real world. New Researc
Initial access. Post-exploitation. Persistence. These are the phases most of you need to simulate in your day-to-day engagements. RustPack can help across all of them. Our latest blog post covers a range of common TTPs and shows how RustPack can help you save time, reduce
Thanks to an exposed server, Rapid7 researchers managed to pull down an attacker's entire toolkit: staged payloads, lure templates, testing files, campaign artifacts & more. That sloppiness offered a rare view of a malware delivery pipeline, end-to-end: https:// r-7.co/3RnpqLC
I'm currently in the crunch phase preparing for Defcon and this time BlackHat to showcase the latest feature of OctoPwn, automation workflows for internal pentest! Here is a little video we put together to show how it works, enjoy!
Two numbers every security leader should sit with: 10 minutes: Average time from initial access to cloud compromise. 10 hours: From vulnerability disclosure to active weaponization. Before your scanner even knows it exists. Most security teams lose every time. The
Proof this week, Bloomberg reports OpenAI's own models escaped a sandboxed eval, found the exploit path, and used it to autonomously breach Hugging Face's production systems.
Registration for Fal.Con Europe 2026 is now open! Join us in Barcelona for three days of bold ideas, practical learning, and the conversations defining the next chapter of the AI Revolution. Register → https:// crwdstr.ke/6012BEW2Kr Barcelona | 2 - 4 November
ThreatDown expands security visibility to AI tools and machine identities
ThreatDown has announced a synchronized expansion of its AI and identity security capabilities to protect organizations from emerging, unmanaged risks. The company launc…
Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication
A high-severity security flaw impacting open-source developer platform Windmill has come under active exploitation in the wild, per VulnCheck. The vulnerability in quest…
CISA orders urgent action on actively exploited Langflow RCE flaw
The Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday ordered U.S. government agencies to prioritize patching an actively exploited vulnerability in the…
1.00general · 22 Jul, 00:34bleepingcomputer.com
FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware
A large-scale operation dubbed 'FakeGit' is pushing SmartLoader and StealC malware through 7,600 malicious GitHub repositories that accumulated more than 14 million down…