• Open

    PLEASE_READ_ME: The Opportunistic Ransomware Devastating MySQL Servers
    Guardicore Labs uncovers a Ransomware detection campaign targeting MySQL servers. Attackers use Double Extortion and publish data to pressure victims.
    The Nansh0u Campaign – Hackers Arsenal Grows Stronger
    In the beginning of April, three attacks detected in the Guardicore Global Sensor Network (GGSN) caught our attention. All three had source IP addresses originating in South-Africa and hosted by VolumeDrive ISP (see IoCs).
    The Oracle of Delphi Will Steal Your Credentials
    Our deception technology is able to reroute attackers into honeypots, where they believe that they found their real target. The attacks brute forced passwords for RDP credentials to connect to the victim download and execute a previously undetected malware, which we named Trojan.sysscan.
    Threats Making WAVs - Incident Response to a Cryptomining Attack
    Guardicore security researchers describe and uncover a full analysis of a cryptomining attack, which hid a cryptominer inside WAV files. The report includes the full attack vectors, from detection, infection, network propagation and malware analysis and recommendations for optimizing incident response processes in data centers.
    Keep Your Tech Flame Alive: Trailblazer Rachel Bayley
    In this Akamai FLAME Trailblazer blog post, Rachel Bayley encourages women to step into the unknown and to be their authentic selves.

  • Open

    Topic Bridge
    CASI leaderboard shifts, and two incidents where AI was handed the keys.
    Weekly Threat Bulletin – June 3rd, 2026
    These are the top threats you should know about this week.
  • Open

    Demand Is Booming for New No Tech, Repairable Tractor
    "There is consumer pressure to back away from technology that is unnecessary to perform everyday tasks."
    Podcast: Hackers Asked Meta AI To Let Them In. It Worked
    The insane Meta AI hack; Amazon's internal AI leaderboard; and our lawsuit against ICE.
    Companies Are Using Reddit to Manipulate ChatGPT and Google AI Search
    Peptide companies have been doing AI-engine optimization by spamming the biohackers subreddit to manipulate ChatGPT and Google.
    Google Is Quietly Buying Code From Play Store Developers to Train AI
    Google is trying to buy code from some Android developers as part of a "confidential" program.
  • Open

    Otto Support - Testing MCP Servers
    MCP servers introduce a new attack surface, but the security fundamentals are familiar. In this final otto-support post, we use nmap, a Nuclei template, and MCP Inspector to discover, enumerate, and exploit an authorization gap without ever touching an LLM.
  • Open

    Optimize AI Inference: Real-Time NodeBalancers Metrics for AI Workloads
    No content preview
  • Open

    Agentic Payments Cross the Threshold: Inside x402’s Path to Meaningful Adoption
    This blog is a preview of our report, “The New Rails: How Digital Assets Are Reshaping the Foundations of Finance.”… The post Agentic Payments Cross the Threshold: Inside x402’s Path to Meaningful Adoption appeared first on Chainalysis.  ( 14 min )
    OFAC Sanctions Nobitex and Major Iranian Cryptocurrency Exchanges in Sweeping Evasion Crackdown
    Summary The Department of the Treasury’s Office of Foreign Assets Control (OFAC) designated four major Iranian cryptocurrency exchanges: Nobitex, Bitpin,… The post OFAC Sanctions Nobitex and Major Iranian Cryptocurrency Exchanges in Sweeping Evasion Crackdown appeared first on Chainalysis.

  • Open

    Identify unused AWS KMS keys and prevent accidental key deletions
    As you scale your use of Amazon Web Services (AWS), managing KMS keys becomes increasingly important. Whether you manage a handful of keys or thousands across multiple AWS accounts and AWS Regions, there’s often a need to audit key usage to help you meet compliance requirements, evaluate your risk posture, and optimize key management costs. […]
    Secure multi-tenant AI agents with Amazon Bedrock AgentCore resource-based policies
    Software as a service (SaaS) providers building AI-powered applications on Amazon Bedrock AgentCore often need to serve multiple tenants with distinct security requirements from a shared infrastructure. Some tenants require cross-account access from their own Amazon Web Services (AWS) accounts, while others mandate that traffic stay within a private virtual private cloud (VPC) for regulatory […]
  • Open

    Microsoft Wants to 'Make People Addicted' to its New AI Assistant, Internal Documents Reveal
    Planning documents for "Scout" say the plan is to "make people addicted" to the tool before adding new features.
    Nvidia and Microsoft Researchers Say AI Agents Don't Care About Safety or Reliability
    The researchers compared AI to the near-sighted cartoon character Mr. Magoo, who can’t see he’s stumbling through dangerous situations.
    Here is the Contract for Palantir’s Super API for the IRS
    The API would make IRS data available to any app the agency wishes. The Criminal Investigation arm of the IRS is also modernizing its own systems.
  • Open

    Highlights from the Akamai India Partner Summit 2026
    No content preview
  • Open

    Infosec News Nuggets — June 2, 2026
    OpenAI Codex Authentication Tokens Stolen in codexui-android npm Supply Chain Attack A malicious supply chain campaign has been stealing OpenAI Codex authentication tokens through a popular npm package called codexui-android, which draws over 29,000 weekly downloads by advertising itself as a legitimate remote web UI for Codex. Unlike typical typosquatting attacks, the exfiltration code was […] The post Infosec News Nuggets — June 2, 2026 appeared first on AboutDFIR - The Definitive Compendium Project.
  • Open

    How I was able to Modify Ratings on a Target and Cause Business Impact
    Learn how I found this interesting bug Continue reading on InfoSec Write-ups »
    Bug Bounty Bootcamp #41: Remote Command Execution — From Innocent Inputs to Full Server Takeover
    A stock checker that pings an IP. A comment box that echoes your name. These simple features hide a terrifying truth: they might be… Continue reading on InfoSec Write-ups »
    The KQL Query That Caught 260 Brute Force Attempts in Microsoft Sentinel
    No content preview
    Auth Mastery Part 2: Sessions, Cookies, and Staying Authenticated
    No content preview
    AI Threat Modelling: A Practical Walkthrough of the TryHackMe Room
    No content preview
    Uncovering the Blind Spot: Bypassing a Security Patch (CVE-2026–24884) to Achieve Arbitrary File…
    No content preview
    One Agent, Five Zero-Days: Turning Past CVEs Into SAST Rules
    No content preview

  • Open

    Chilling Effects of Trump’s War on Free Speech Extend Far Beyond Campus Walls – And That’s the Point
    Citizen Lab senior research fellow Jon Penney and co-author Bruce Schneier wrote an op-ed in The Conversation about chilling effects. The post Chilling Effects of Trump’s War on Free Speech Extend Far Beyond Campus Walls – And That’s the Point appeared first on The Citizen Lab.
  • Open

    Amazon Shuts Down Internal AI Leaderboard After Employees Cheated
    Employees admitted to 404 Media they had cheated to climb the leaderboard's ranks.
    Hackers Simply Asked Meta AI to Give Them Access to High-Profile Instagram Accounts. It Worked
    The exploit shows the extreme risk of offloading technical support to AI.
    We Sued ICE to Get Its Spyware Contract. The Agency Is Redacting Essentially Everything
    Paragon's software is capable of remotely breaking into phones and accessing messages from encrypted messaging apps. Our lawsuit aims to pry records about it from ICE.
    AI Grifters Are Making Anti-Data Center Slop With AI
    There are hundreds of anti-data center Facebook pages churning out AI-generated slopaganda.
  • Open

    Spring 2026 SOC 1, 2, and 3 reports are now available with 188 services in scope
    Amazon Web Services (AWS) is pleased to announce that the Spring 2026 System and Organization Controls (SOC) 1, 2, and 3 reports are now available. The reports cover 188 services over the 12-month period from April 1, 2025–March 31, 2026, giving customers a full year of assurance. These reports demonstrate our continuous commitment to adhering […]
  • Open

    InfoSec News Nuggets — June 1, 2026
    Signal Phishing Campaign Targets Journalists and Activists to Steal Backup Recovery Keys A targeted phishing campaign is sending text messages that impersonate Signal Support, urgently requesting users paste their 64-character backup recovery key into the chat. Unlike standard account takeovers that only expose future messages, stealing the recovery key gives attackers full access to the […] The post InfoSec News Nuggets — June 1, 2026 appeared first on AboutDFIR - The Definitive Compendium Project.
  • Open

    How Bug Bounty Hunters Are Using Claude Code.
    The community has been quietly building something powerful. I went and found it. Continue reading on InfoSec Write-ups »
    Common Mistakes Made by Cybersecurity Beginners
    No content preview
    Google Dorks Google Ko Bana Do Apna Hacking Tool: Free Mein Bugs Dhundho! (Hinglish Mein)
    No content preview

  • Open

    Scala Security Audit
    The Scala team has partnered with the Open Source Technology Improvement Fund (OSTIF) to conduct its first security audit. This initiative aims to identify potential vulnerabilities through static and dynamic analysis and provide greater confidence in Scala. The security audit conducted by Quarkslab is particularly focused on Scala 3.

  • Open

    📖 [The CloudSecList] Issue 340
    📖 [The CloudSecList] Issue 340 was originally published by Marco Lancini at CloudSecList on May 31, 2026.
  • Open

    ‘Highly Plausible’ Aliens on Europa Are Earthlings’ Descendants, Study Says
    A new study suggests that bacteria dispersed through space on dust grains could potentially arrive intact and alive on Jupiter’s moon Europa.

  • Open

    Behind the Blog: Being New and Some Numbers
    This week, we discuss going deeper and Google's search changes.
    New Study Reveals the Manipulative ‘Dark Patterns’ of AI Chatbots
    A new study by the Center for Democracy & Technology shows how chatbots like ChatGPT, Gemini, Replika and more can lead users down paths they didn't intend.
  • Open

    Researchers Uncover Espionage in Mobile Networks
    Swantje Lange spoke with the Hasso Plattner Institut about sophisticated surveillance campaigns being used to exploit mobile networks. The post Researchers Uncover Espionage in Mobile Networks appeared first on The Citizen Lab.
  • Open

    Looting UniFi Controllers: Detecting and Weaponizing CVE-2026-22557
    A CVSS 10.0 path traversal in UniFi Network Application lets unauthenticated attackers read controller backups, extract credentials, and take over every managed device on the network. Bishop Fox breaks down the attack paths, the preconditions, and a safe detection tool to check your exposure.
  • Open

    InfoSec News Nuggets – 05/29/2026
    Carnival Cruise Confirms Data Breach Affecting Nearly 6 Million People Carnival Corporation, the world’s largest cruise line operator, began notifying nearly 6 million customers this week that their personal data was stolen in an April breach after attackers gained access to an employee account through a social engineering attack. The stolen data varies by individual […] The post InfoSec News Nuggets – 05/29/2026 appeared first on AboutDFIR - The Definitive Compendium Project.

  • Open

    Why and how to migrate to a Transit Gateway-attached AWS Network Firewall
    AWS Network Firewall now supports native attachment to AWS Transit Gateway. Customers commonly use Transit Gateway to route traffic from Amazon Virtual Private Cloud (Amazon VPC) networks to a centralized inspection VPC (a VPC dedicated to hosting firewall endpoints for traffic inspection) where their network firewall endpoints are deployed. This centralized deployment model reduces the […]
    Simplifying policy management with URL and Domain Category filtering on AWS Network Firewall
    Network administrators face a persistent challenge: maintaining domain blocklists and allowlists that keep pace with the internet. New websites and services emerge daily, and keeping these lists current requires constant manual updates that leave gaps in coverage. This challenge intensifies when managing access to rapidly evolving categories like AI services, where new tools launch on […]
  • Open

    Cities Are Covering Flock Cameras With Trash Bags
    Regretful cities aren't sure how to cancel their surveillance contracts, so they are literally covering their cameras.
  • Open

    Consistent Protections Without Compromise: Akamai’s WAF Is Now on AWS Marketplace
    No content preview
  • Open

    InfoSec News Nuggets – 05/28/2026
    FBI Warns Silent Ransom Group Is Walking Into Law Firm Offices to Steal Data The FBI issued a fresh flash alert warning that Silent Ransom Group — also known as Luna Moth, Chatty Spider, and UNC3753 — has escalated its campaign against U.S. law firms by physically sending operatives into offices posing as IT support […] The post InfoSec News Nuggets – 05/28/2026 appeared first on AboutDFIR - The Definitive Compendium Project.

  • Open

    The Small Model Cliff
    CASI Leaderboard, Bias Jailbreak, and Three Coordinated Supply Chain Incidents
    Weekly Threat Bulletin – May 27th, 2026
    These are the top threats you should know about this week.
  • Open

    The New Compliance Floor: Organizations are Adopting Stronger Than Ever Monitoring Practices
    This blog is a preview of our report, “The New Rails: How Digital Assets Are Reshaping the Foundations of Finance.”… The post The New Compliance Floor: Organizations are Adopting Stronger Than Ever Monitoring Practices appeared first on Chainalysis.  ( 15 min )
    U.K. Sanctions 18 Entities and Persons for Evading Russian Trade Blockades
    Summary The U.K.’s Foreign, Commonwealth and Development Office (FCDO) sanctioned 18 cryptocurrency exchanges, payment providers, and individuals for helping Russia… The post U.K. Sanctions 18 Entities and Persons for Evading Russian Trade Blockades appeared first on Chainalysis.  ( 12 min )
  • Open

    InfoSec News Nuggets 05/27/2026
    AI Chatbot Recommendations Redirect Users to Cryptojacking Malware Sites Microsoft warned that attackers are adapting SEO poisoning techniques for AI-generated software recommendations, pushing users toward fake utility download sites that deploy ScreenConnect for persistence before launching cryptomining payloads. The campaign is a meaningful shift in social engineering surface area — users who have learned to […] The post InfoSec News Nuggets 05/27/2026 appeared first on AboutDFIR - The Definitive Compendium Project.
  • Open

    Distributed AI Inference: Why Placement Is the New Bottleneck
    In real AI systems, bottlenecks don't disappear, they move. Learn about why inference placement, not raw compute, is the decisive infrastructure question.

  • Open

    Welcoming the AWS Customer Incident Response Team
    May 26, 2026: This post was originally published in July 2022. It has been updated to reflect current engagement options, new threat intelligence resources such as the Threat Technique Catalog for AWS (TTC), additional open-source tools, and the distinction between AWS CIRT support and the AWS Security Incident Response managed service. Welcome back, or welcome […]
    Well-architected best practices for software supply chain security
    There have been multiple notable supply chain attacks using the npm Registry since September: Shai-Hulud, Chalk/Debug, one abusing tea.xyz tokens, and recently axios. Thanks to community efforts involving the Amazon Inspector team, the Open Source Security Foundation, and others, the affected packages were quickly flagged, which reduced the impact of these incidents. Supply chain attacks […]
  • Open

    Introducing Password-Less Provisioning and Atomic Customization for VMs
    Akamai Cloud introduces password-less provisioning and atomic customization. Align with Zero Trust by eliminating root passwords and hardening VMs at creation.
  • Open

    Sparkplug B Protocol Fuzzing with AI Assistance
    Sparkplug B is the dominant protocol in ICS and SCADA environments, but no public security fuzzer existed for it until now. Bishop Fox used AI-assisted development to build one from scratch, covering all 9 message types, 19 data types, and 87+ field paths from the full specification.
  • Open

    InfoSec News Nuggets 05/26/2026
    Iranian Hackers Deploy MiniFast and MiniJunk V2 via Phishing and SEO Poisoning Researchers tied a fresh Nimbus Manticore campaign to phishing and SEO poisoning targeting aviation, software, telecom, and oil and gas organizations across the U.S., Europe, and the Middle East, using fake career lures, trojanized Zoom and SQL Developer installers, and new backdoors called […] The post InfoSec News Nuggets 05/26/2026 appeared first on AboutDFIR - The Definitive Compendium Project.

  • Open

    Trump Wants to Tap Your Phone. Ottawa Might Let Him.
    Senior research associate Kate Robertson discusses the risks Bill C-22 poses for future data-sharing agreements with foreign law enforcement agencies. The post Trump Wants to Tap Your Phone. Ottawa Might Let Him. appeared first on The Citizen Lab.

  • Open

    📖 [The CloudSecList] Issue 339
    📖 [The CloudSecList] Issue 339 was originally published by Marco Lancini at CloudSecList on May 24, 2026.

  • Open

    OFAC and Crypto Crime: Every OFAC Specially Designated National with Identified Cryptocurrency Addresses
    As far back as the early 1800s, the U.S. Department of the Treasury has issued economic sanctions to achieve foreign… The post OFAC and Crypto Crime: Every OFAC Specially Designated National with Identified Cryptocurrency Addresses appeared first on Chainalysis.  ( 28 min )
  • Open

    Detecting CVE-2026-0265 at Scale: PAN-OS CAS Authentication Bypass
    CVE-2026-0265 lets unauthenticated attackers forge a JWT and log in as any trusted user on CAS-enabled PAN-OS deployments. Bishop Fox built a detection tool that returns a definitive verdict from a single anonymous request, and breaks down exactly how the bug works and what to do about it.
    CVE-2026-27886: Unauthenticated Boolean-Oracle Exfiltration of Administrator Secrets in Strapi
    A sanitization bypass in Strapi 4.0.0 through 5.36.1 lets unauthenticated attackers extract an admin's password reset token character by character and take over the account. With over 20,000 internet-facing hosts exposed, Bishop Fox breaks down how the exploit works and how to remediate it.
  • Open

    InfoSec News Nuggets 05/22/2026
    TrendAI Patches Apex One Zero-Day Exploited in the Wild TrendAI patched CVE-2026-34926, a directory traversal flaw in the on-premises version of Apex One that has been exploited in the wild, with successful abuse allowing an attacker to modify a key table and inject malicious code for deployment to managed agents. Exploitation requires access to the […] The post InfoSec News Nuggets 05/22/2026 appeared first on AboutDFIR - The Definitive Compendium Project.

  • Open

    Decentralized Threat: Stealthy P2P Cryptominer Targeting Ollama Endpoints
    The Akamai SIRT uncovered a custom P2P Trojan masquerading as system activity. Learn how to detect and mitigate this stealthy Go-based cryptominer.
    Secure Identity at the Edge: Akamai Partners with Auth0
    The Akamai and Auth0 partnership secures identity at the edge by combining edge intelligence and adaptive authentication to stop fraud and enhance user trust.
    CVE-2026-9082: Mitigating a Critical SQL Injection Vulnerability in Drupal
    Learn how the complex Drupal SQLi vulnerability (CVE-2026-9082) exploits PostgreSQL environments and its data theft risks — and how to ensure you’re protected.
  • Open

    AWS KY3P report now available for third-party supplier due diligence
    We’re excited to announce that Amazon Web Services (AWS) has completed the S&P Global Know Your Third Party (KY3P) assessment of its security posture. This assessment demonstrates our continued commitment to meet the heightened expectations of cloud service providers. Customers can now use the AWS KY3P assessment to reduce their supplier due diligence burden. KY3P, […]
    Automating identity lifecycle and security with AWS Directory Service APIs
    Managing identities and access across complex environments has become more critical than ever. AWS Directory Service for Managed Microsoft Active Directory, also known as AWS Managed Microsoft AD, has added new capabilities to manage users and groups. Now, you can perform create, read, update, and delete (CRUD) operations on users and groups directly through AWS […]
  • Open

    InfoSec News Nuggets 05/21/2026
    Highly Critical Drupal Core Flaw Exposes PostgreSQL Sites to RCE Attacks Drupal released security updates for CVE-2026-9082, a highly critical flaw affecting sites that use PostgreSQL databases, which can allow anonymous attackers to send crafted requests leading to SQL injection, information disclosure, privilege escalation, or remote code execution in some cases. Teams running Drupal should […] The post InfoSec News Nuggets 05/21/2026 appeared first on AboutDFIR - The Definitive Compendium Project.

  • Open

    OFAC Sanctions Sinaloa Cartel Fentanyl Trafficking and Crypto Laundering Network
    Summary The Department of the Treasury’s Office of Foreign Assets Control (OFAC) sanctioned more than a dozen individuals and entities… The post OFAC Sanctions Sinaloa Cartel Fentanyl Trafficking and Crypto Laundering Network appeared first on Chainalysis.
    How Blockchain Intelligence Uncovered a Million-Euro Bitcoin Ordinals Tax Fraud Scheme
    Summary Criminals are increasingly turning to novel digital asset classes, like Bitcoin Ordinals and BRC-20 tokens, to generate and conceal… The post How Blockchain Intelligence Uncovered a Million-Euro Bitcoin Ordinals Tax Fraud Scheme appeared first on Chainalysis.  ( 13 min )
  • Open

    Why Policy in Amazon Bedrock AgentCore chose Cedar for securing agentic workflows
    Agents have agency: they adapt and find multiple ways to solve problems. This autonomy creates a fundamental security challenge: the large language model (LLM) at the heart of the agent is non-deterministic, and its decisions can’t be predicted or guaranteed in advance. It can hallucinate harmful actions with complete confidence. It’s vulnerable to prompt injection […]
    AWS Security Hub Extended: Why enterprise security products should sell themselves
    Our largest security services customers started the same way every customer does – with a click. They enabled Amazon GuardDuty, Amazon Inspector, AWS WAF, and AWS Security Hub, experienced the benefits in real time, and evaluated with transparent pay-as-you-go pricing. No RFP. No six-month evaluation. No multi-year commitment up front. Our field teams played a […]
  • Open

    Weekly Threat Bulletin – May 20th, 2026
    These are the top threats you should know about this week.
  • Open

    InfoSec News Nuggets 05/20/2026
    GitHub Investigates Internal Repositories Breach Claimed by TeamPCP GitHub confirmed that roughly 3,800 internal repositories were accessed after an employee installed a malicious VS Code extension, in what appears to be a follow-on from the broader developer tooling supply chain attack activity seen this week. The company says it has no evidence that customer repositories, […] The post InfoSec News Nuggets 05/20/2026 appeared first on AboutDFIR - The Definitive Compendium Project.
  • Open

    This Is a Hold-Up: Financial Services Under Attack
    No content preview

  • Open

    Microsoft Exchange ProxyShell Scanning Doubles in April 2026 as Two Distinct Campaign Clusters Emerge
    Sensor Intel Series: April 2026 CVE Trends
  • Open

    CIRT insights: How to help prevent unauthorized account removals from AWS Organizations
    The AWS Customer Incident Response Team works with customers to help them recover from active security incidents. As part of this work, the team often uncovers new or trending tactics used by various threat actors that take advantage of specific customer configurations and designs. Understanding these tactics can help inform your architecture decisions, improve your […]
    Governing infrastructure as code using pattern-based policy as code
    Organizations often struggle to enforce security and compliance requirements consistently across their cloud infrastructure. In one environment, a workload might be deployed in an AWS Region that was never approved for that class of data. In another, a security group might allow broader access than intended. Required tags might be missing. Encryption might be assumed […]
  • Open

    InfoSec News Nuggets – 05/19/2026
    Nx Console VS Code Extension Compromised A compromised version of the Nx Console VS Code extension, version 18.95.0, was briefly published with malicious code targeting developer credentials, cloud tokens, CI/CD secrets, Kubernetes credentials, 1Password data, and AI coding assistant configuration files. The extension has more than 2.2 million installs, and the malicious version executed when […] The post InfoSec News Nuggets – 05/19/2026 appeared first on AboutDFIR - The Definitive Compendium Project.

  • Open

    How OLTs may have exposed entire ISP networks
    An Optical Line Terminal (OLT) is the central device in a Fiber-To-The-Home (FTTH) network that connects and manages all customer connections, making it a critical control point in an ISP's infrastructure for delivering high speed Internet. This article uncovers how unauthenticated access to OLTs can lead to a full network takeover starting by exploiting exposed vulnerable devices, showing how to pivot into the cloud-based fleet manager using other vulnerabilities, and then compromising an ISP's entire infrastructure.
  • Open

    CVE-2026-42945: Mitigating a Critical Heap Buffer Overflow Vulnerability in NGINX
    Discover CVE-2026-42945 (NGINX Rift), a critical heap buffer overflow vulnerability. Learn about the affected versions and critical patch updates.

  • Open

    📖 [The CloudSecList] Issue 338
    📖 [The CloudSecList] Issue 338 was originally published by Marco Lancini at CloudSecList on May 17, 2026.

  • Open

    The AWS AI Security Framework: Securing AI with the right controls, at the right layers, at the right phases
    May 26, 2026: We’ve updated this post to reflect recommended core services. TL;DR for busy executives The AWS AI Security Framework helps security leaders move fast and stay secure with AI. Security compounds from day 1 as workloads evolve from prototype to production to scale. Assess first. Request a no-cost SHIP engagement to baseline your […]
  • Open

    Mini Shai-Hulud: The Worm Returns and Goes Public
    No content preview

  • Open

    Regional routing for AWS access portals: Implementing custom vanity domains for IAM Identity Center
    AWS IAM Identity Center provides a web-based access portal that gives your workforce a single place to view their AWS accounts and applications. With the recent launch of IAM Identity Center multi-Region replication, customers can replicate their IAM Identity Center instance across multiple AWS Regions to improve resilience and reduce latency for a globally distributed […]
    Automating post-quantum cryptography readiness using AWS Config
    Migrating your TLS endpoints to Post-quantum cryptography (PQC) starts with understanding your current TLS endpoint inventory and posture. This post introduces the PQC Readiness Scanner — an automated tool that inventories your Application Load Balancer (ALB), Network Load Balancer (NLB), and Amazon API Gateway endpoints and continuously monitors their TLS configurations for PQC readiness. The […]
  • Open

    Signal Warns It Would Pull Out of Canada if Made to Comply with Lawful Access Bill
    Senior research associate Kate Robertson says Bill C-22 could lead to the rollout of forced metadata collection for messaging apps. The post Signal Warns It Would Pull Out of Canada if Made to Comply with Lawful Access Bill appeared first on The Citizen Lab.
  • Open

    The Internet Has a Front Door — The Edge Is Now Intelligent
    Recent improvements in the capabilities of the edge network have created a smarter, more connected edge. These changes call for a reassessment of edge strategy.
  • Open

    Otto Support - Logging and Visibility in MCP Servers
    If any of the MCP attack classes in this series happened in your environment today, would you detect it? Most MCP servers log only a tool name and a timestamp. This post walks through what that gap looks like in practice, how EchoLeak exploited it, and what proper audit logging actually requires.

  • Open

    Detecting and preventing crypto mining in your AWS environment
    This article guides you on how to use Amazon GuardDuty to identify and mitigate cryptocurrency mining threats in your Amazon Web Services (AWS) environment. You’ll learn about the specialized detection capabilities of GuardDuty and best practices to build a multi-layered defense strategy that protects your infrastructure costs and security posture. Understanding the crypto mining challenge […]
    Introducing the updated AWS User Guide to Governance, Risk, and Compliance for Responsible AI Adoption
    The financial services industry (FSI) is using AI to transform how financial institutions serve their customers. AI solutions can help proactively manage portfolios, automatically refinance mortgages when rates decrease, and negotiate insurance premiums for customers. However, this adoption brings new governance, risk, and compliance (GRC) considerations that organizations need to address. To help FSI customers […]
    PCI PIN and P2PE compliance packages for AWS Payment Cryptography are now available
    Amazon Web Services (AWS) is pleased to announce the successful completion of Payment Card Industry Personal Identification Number (PCI PIN) and PCI Point-to-Point Encryption (PCI P2PE) assessments for the AWS Payment Cryptography service. This assessment expands the AWS Payment Cryptography compliance portfolio, with AWS now validated as a component provider for Key Management (KMCP) and […]
  • Open

    Ron Deibert Speaks at the OSCE: Supplementary Human Dimension Meeting II
    Citizen Lab director Ron Deibert recently spoke at the OSCE Supplementary Human Dimension Meeting II on Safeguarding Civil Space in the Digital Age. The post Ron Deibert Speaks at the OSCE: Supplementary Human Dimension Meeting II appeared first on The Citizen Lab.
  • Open

    Weekly Threat Bulletin – May 13th, 2026
    These are the top threats you should know about this week.
  • Open

    Otto-Support - Supply Chain Risks in MCP Servers
    What if the MCP server itself is the attacker? Supply chain risk in MCP tools is structural, and the postmark-mcp and ClawHub compromises made it concrete. This post pairs those case studies with otto-support's selfpwn module to show exactly what a hostile MCP server can access the moment it runs.

  • Open

    AWS Security Agent full repository code scanning feature now available in preview
    Today, we’re excited to announce the preview release of full repository code review, a new capability in AWS Security Agent that performs deep, context-aware security analysis of your entire code base. AI-driven cybersecurity capabilities are advancing rapidly. AWS Security Agent can now find vulnerabilities and build working exploits across your entire code base at a […]
  • Open

    One Is a Fluke, 3 Is a Pattern: MCP Back-End Vulnerabilities
    No content preview
  • Open

    Introducing Joro: Using AI to Build Security Tooling
    Bishop Fox is releasing Joro, a collaborative web exploitation framework built almost entirely with AI. From intercepting proxy to C2 integration, this post covers how it was built, what it does, and what AI-assisted security tool development actually looks like in practice.

  • Open

    Advancing Collective Defense with Project Glasswing
    No content preview

  • Open

    📖 [The CloudSecList] Issue 337
    📖 [The CloudSecList] Issue 337 was originally published by Marco Lancini at CloudSecList on May 10, 2026.

  • Open

    Otto Support - The Confused Deputy
    When an agent reads attacker-controlled content and acts on it using its own privileges, the user's name ends up on every audit log entry. From Microsoft Copilot to ConfusedPilot, this post walks through how confused deputy attacks work and the layered controls that help contain them.
  • Open

    CVE-2026-34354: Guardicore Local Privilege Escalation Vulnerability
    Read the technical details of a security vulnerability (CVE-2026-34354) in Akamai Guardicore Platform Agent for Windows — and get clear guidance on mitigation.

  • Open

    Crypto Prediction Markets Explained: How the Blockchain Is Reshaping Forecasting
    Summary Crypto prediction markets use blockchain technology to create liquid platforms for forecasting and hedging real-world events, driving massive growth… The post Crypto Prediction Markets Explained: How the Blockchain Is Reshaping Forecasting appeared first on Chainalysis.
  • Open

    Otto Support - SSRF and Token Passthrough with MCP
    SSRF and token passthrough are not new, but MCP servers are reintroducing them at scale. From a chained SSRF-to-RCE in mcp-atlassian to Microsoft's MarkItDown and OpenClaw, this post walks through three recent disclosures and the controls that actually prevent them.

  • Open

    The IGVM File Format
    This article presents the structure of the Independent Guest Virtual Machine (IGVM) file format, a binary file designed to define and securely launch the initial state of a virtual machine. It bundles all necessary components such as the BIOS/OVMF, kernel, and initial ramdisk, into a single file. We'll focus on a concrete example to understand the main structure of the file format.
  • Open

    Weekly Threat Bulletin – May 6th, 2026
    These are the top threats you should know about this week.
  • Open

    AI Survey: 50% of Organizations Struggle to Maintain Latency at Scale
    The Akamai State of AI Inference report captures real data from the field that describes how AI inference is being built and scaled in production today.
    Akamai Is the 2026 Gartner® Peer Insights™ Customers’ Choice for API Protection
    Read why Akamai was named the only Customers’ Choice in the 2026 Gartner Peer Insights Voice of the Customer for API Protection.
    Akamai Cloud Is Built for What Cloud Has Become (Updated May 2026)
    No content preview
  • Open

    Otto Support - Excessive Agency and Tool Privileges
    AI agents connected to too many tools don't just create risk, they've already caused real damage. From deleted databases to mass-wiped mailboxes, excessive agency has a track record. This post breaks down what it looks like in practice and how role-aware tool registration can help contain it.
    CVE-2026-42208: Pre-Authentication SQL Injection in LiteLLM Proxy
    Bishop Fox researchers confirmed a critical pre-authentication SQL injection in LiteLLM proxy affecting versions 1.81.16 through 1.83.6. Attackers can exploit it without credentials, and it blends into normal logs. In-the-wild exploitation was observed within 36 hours of the advisory going public.
  • Open

    Where to Build: A Data-Driven Guide to Blockchain Infrastructure for TradFi Tokenization
    This blog is a preview of our report, “The New Rails: How Digital Assets Are Reshaping the Foundations of Finance.”… The post Where to Build: A Data-Driven Guide to Blockchain Infrastructure for TradFi Tokenization appeared first on Chainalysis.  ( 19 min )
2026-06-04T04:04:24.968Z osmosfeed 1.15.1