If you see them, it's already too late. 🐈
If you see them, it's already too late. 🐈
A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escala…
The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE).
Attackers modified a JavaScript file served by advertising technology company Adform, turning it into a browser-side tool that rewrites cryptocurrency wallet addresses.
Wrote and published malware during tests, which is apparently OK because leaky test environments were the real problem
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a data leak in which a contractor published dozens of internal CISA credentials …
Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizations such a…
A Millisecond of Predictability: Why CVE-2026-11374 Is Hard to Exploit
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition. The following versio
OpenAI shares new results on long-standing open problems in mathematics and theoretical computer science, including advances in geometry, cryptography, and complexity.
See how Wiz built Atlas, an autonomous AI system for vulnerability research that validates every finding with a real, working exploit.
TL;DR: The OpenAI agent’s attack on Hugging Face showed how quickly AI can chain vulnerabilities, steal credentials, and move through an environment.
New report analyzes the first publicly documented fully autonomous cyberattack and delivers practical steps security leaders should take to strengthen their AI resilie…
AI is accelerating software development and giving attackers machine-speed capabilities.
The Origin Energy breach down here in Aus is all over the news this week, and as with many breaches, it's multi-faceted.
Why we’re launching the program What it means to be a Burp Ambassador What we’re aiming for Our Burp Ambassadors Alan Levy Corey Ball Federico Dotta Rana Khalil Tib3ri…
Less than a year after emerging from stealth to tackle non-human identity security, Israeli cybersecurity startup Hush Security believes the enterprise AI security con…
The deal is Cyera's third acquisition this year.
Open-source XDR/SIEM for threat detection and compliance.
Relevance: Detection & response / compliance
Template-based vulnerability scanner for massive-scale network scanning.
Relevance: Offensive security & recon
Comprehensive scanner for containers, IaC, and dependencies.
Relevance: Cloud & container defenders
Interactive TLS-capable intercepting proxy for traffic analysis.
Relevance: AppSec & traffic inspection
Swiss-army toolkit for network attacks, MITM and recon.
Relevance: Network penetration testing
Passive subdomain enumeration from dozens of sources.
Relevance: Recon & attack-surface mapping
Graph-based Active Directory relationship explorer for attack paths.
Relevance: Red teams & AD assessment
Look at all the fleeced crypto idiots, say the people holding lots of cryptocurrencies (and who themselves have been robbed, rug-pulled or scammed multiple times over the years). The crypto noobs are doing it all wrong, they say: The only safe way to store your crypto wealth is in an offline hardware wallet that would require physical theft to steal your coins. But this is now cold comfort for users of the hardware wallet Coldcard, which had a flaw that traces to a March 2021 firmware build which "routed seed generation to a predictable software randomiser instead of the chip’s hardware one, leaving a bounded set of possible keys that anyone with the disclosure and enough compute can reproduce offline, without ever touching a device.""Galaxy Research flagged a third wave of sweeps early Sunday, roughly 208 bitcoin drained from 1,912 addresses between Friday midday and Saturday morning UTC.That is just over a tenth of a bitcoin per victim. The July 30 opening wave averaged close to a full coin, 1,083 bitcoin from 1,196 addresses in 41 minutes.Observed losses across all three waves now total 1,367 bitcoin, nearly $89 million, from 4,585 addresses."https://www.coindesk.com/tech/2026/08/02/bitcoin-cold-wallet-attack-spreads-to-4-500-addresses-as-losses-near-usd89-million
Does anyone have a contact at warner bros? I found several very detrimental security issues there, and their hacker one team is unresponsive.Thanks
Google is preparing a new Chrome security feature that would block policy-installed extensions from hijacking the New Tab page or changing the default search engine.https://www.bleepingcomputer.com/news/google/google-chrome-may-soon-block-new-tab-hijacker-extensions-by-default/
RE: https://infosec.exchange/@pasi/117013518187746016Kartasto/Maptrails is by far the best map app out there for looking at maps on the mobile. It even supports custom maps so you can feed it your local municipality map if that's better than what is already included. Previously figuring out what exact url format maptrails needs was a bit annoying but the agents will dig that out.The best part is that it's a side project (afaik) not the main source of income so a one time purchase. Also no UI team who needs to redesign it every 12 months to motivate their existence.My favourite kind of apps.
RE: https://infosec.exchange/@AmmarSpaces/117012462419438976There's a slight update regarding this event.Jakarta (Indonesia's capital) province administration rolled out an order for malls and banks in Jakarta to remove these high fences, because they are thinking this might cause paranoid to people, fearing people think something bad will happen this August.My personal opinion, are still the same, don't come to Indonesia until there is a sure news in the next month (September), nothing bad happen.@indonesia #indonesia #jakarta #security