Generated 23/06/2026, 09:28. Pipeline: Europe/Belgrade. Regular sources favor exploit, blog, red-team, and attack-path content. CVE items only stay with exploit signal.
Total items15
Regular sources3
Tweets / X12
Threshold0.62
You can save this report in your browser with the favorite button. If you need a shared favorite list, use the CLI helper.
Tweets / X
12 items
Sysdig @Sysdig
22 Jun, 23:57 · secondary
0.59
An operator RCE'd a Langflow box, swept env vars, and stole Azure service principal creds, then LLMjacked an Azure AI Foundry endpoint serving Anthropic models. AWS is easy to catch: everyone has CloudTrail. Azure is tough: few stream Entra sign-ins, so a stolen SP trips
The @x33fcon conference was once again a complete success! I wanted to share the slides and demo videos from the "Downgrading FIDO MFA With AI Slop" talk I gave on the second day (the next day after the pirate ship party... ugh). Slides: https:// github.com/kgretzky/talks /tree/m
We're excited to partner with @OpenAI through the Daybreak Cyber Partner Program to help defenders solve one of cybersecurity's toughest challenges: attack path triage. The challenge isn't finding risk. It's knowing which attack paths matter most.
FortiBleed is a large-scale password spraying and credential theft campaign targeting Fortinet, Sophos and MSSQL devices. Threat actors are using a curated password list developed through previous breaches and vulnerability exploits. We detail mitigations: https:// bit.ly/4eDxSxY
I just wrote a new blog on bypassing CA policies in Entra ID that have a resource exclusion, and why you probably want to enable baseline enforcement if you have such policies. Enjoy!
Hello 1. If you're reading this, that means you live inside my computer. Please leave my computer. You are stinking the place up. 2. I am syncing 150,000+ malwares to the internet. Please download the malware. 3. I now possess 14TB (7z ultra compressed) of malware
Is there an existential threat to ProjectDiscovery? We aren’t buying into the AI "psychosis" or "apocalypse" narrative. Instead, our focus remains on ensuring we consistently deliver high value to the security community. Staying ahead means moving faster.
12 out of 15 top-tier hackers ignore standard security methodologies. New research into hacker cognition reveals that elite researchers don’t follow rigid checklists when testing a target. Instead, they rely on fast, intuitive pattern recognition built from years of
LLMjacking has evolved. A threat actor used an exposed Ollama server as the brain for an autonomous, multi-stage offensive hacking tool. Not reselling access. Building with it. Sysdig TRT caught the tool while it was still in development. Full research:
Research or Content? 3 Rules Most security research out there isn't research. It's content. There's a difference, and it comes down to three things. 1. Correct and Defensible Every claim, every payload, every technique must hold under scrutiny. Not "it worked once in my lab."
Agent Beacon: Open-source telemetry layer for AI agents
AI coding agents such as Claude Code, Codex CLI, Cursor, and Claude Cowork run on developer laptops, CI jobs, cloud environments, where they edit files, run commands, an…
0.97exploit · 22 Jun, 20:172 mentionsseclists.org
Re: Proposal: Add separate oss-security-vulnerability-reports mailing list (for AI vulnpocalypse)
Posted by Jeremy Stanley on Jun 22 [...] It's both... Yes advance notification in the case of embargoed vulnerabilities is going to the linux-distros mailing list as wel… | Posted by Sylvain Beucler on Jun 22 Hello Jeremy, Interesting. This seems like an embargo-like workflow, usually for high/critical CVEs, which I believe won't involve se…
What the Latest ShinyHunters Breaches Reveal About Modern Cyberattacks
Groups like ShinyHunters are demonstrating that attackers do not necessarily need malware or zero-day exploits to cause massive damage. The post What the Latest ShinyHun…