• Open

    PLEASE_READ_ME: The Opportunistic Ransomware Devastating MySQL Servers
    Guardicore Labs uncovers a Ransomware detection campaign targeting MySQL servers. Attackers use Double Extortion and publish data to pressure victims.
    The Nansh0u Campaign – Hackers Arsenal Grows Stronger
    In the beginning of April, three attacks detected in the Guardicore Global Sensor Network (GGSN) caught our attention. All three had source IP addresses originating in South-Africa and hosted by VolumeDrive ISP (see IoCs).
    Threats Making WAVs - Incident Response to a Cryptomining Attack
    Guardicore security researchers describe and uncover a full analysis of a cryptomining attack, which hid a cryptominer inside WAV files. The report includes the full attack vectors, from detection, infection, network propagation and malware analysis and recommendations for optimizing incident response processes in data centers.
    The Oracle of Delphi Will Steal Your Credentials
    Our deception technology is able to reroute attackers into honeypots, where they believe that they found their real target. The attacks brute forced passwords for RDP credentials to connect to the victim download and execute a previously undetected malware, which we named Trojan.sysscan.
    Keep Your Tech Flame Alive: Trailblazer Rachel Bayley
    In this Akamai FLAME Trailblazer blog post, Rachel Bayley encourages women to step into the unknown and to be their authentic selves.
  • Open

    Infinite Campus - 137,123 breached accounts
    In March 2026, the student information system Infinite Campus was targeted in a ShinyHunters "pay or leak" extortion campaign. The group subsequently published data they alleged was taken from Infinite Campus, containing 137k unique email addresses along with names, phone numbers, physical addresses and support tickets. Infinite Campus subsequently sent notifications, advising that the exposed data largely consisted of "names and contact information for school staff" and that "the majority is directory information commonly found on school websites".

  • Open

    ContinuumCon 2026 - Day 3
    No content preview

  • Open

    📖 [The CloudSecList] Issue 342
    📖 [The CloudSecList] Issue 342 was originally published by Marco Lancini at CloudSecList on June 14, 2026.
  • Open

    ContinuumCon 2026 - Day 2
    No content preview
  • Open

    Scientists Discover Vast Ancient ‘Necropolis’ Teeming With Strange New Creatures
    A massive whale graveyard in the Indian Ocean contains the remains of hundreds of extinct whales dating back more than five million years, along with recent carcasses that support hotspots of seafloor life.

  • Open

    ContinuumCon 2026 - Day 1
    No content preview
    Payload Podcast 008 - Ryan Hausknecht
    No content preview
  • Open

    Attacking AI Video Processing | Patrick Double
    No content preview
  • Open

    Canada Finally Has a National AI Strategy. Experts Hate It.
    Senior fellow Cynthia Khoo writes that “pillars core to a functioning democracy are [being] reoriented around the false god of AI” in The Walrus.  The post Canada Finally Has a National AI Strategy. Experts Hate It. appeared first on The Citizen Lab.
    Who Watches the Watchers?
    Citizen Lab director Ron Deibert spoke to Politiken about the spyware industry, calling it “a symptom that something is fundamentally wrong.”  The post Who Watches the Watchers? appeared first on The Citizen Lab.
    Luis Fernando García On State Surveillance in Latin America
    Senior researcher Luis Fernando García participated in a Conversatorio Regional hosted by CELS, ODIA, Democracia en Red, and Vía Libre. The post Luis Fernando García On State Surveillance in Latin America appeared first on The Citizen Lab.
  • Open

    ‘You Will Not Speak on Flock Tonight’: County Commissioner Refuses to Let Residents Opposing Flock Speak at Meeting
    "I’ve spoken. I’m not debating this."
    Behind the Blog: World Cup Madness and Film Reviews
    This week, we discuss Trump fucking up the World Cup, some thoughts on ICE coverage, and movies.
  • Open

    Stolen iPhones could soon be worth a lot less to thieves
    Apple and the Met Police are working together to make stolen iPhones harder to reset, resell, and profit from.  ( 23 min )
    Fake verification pages are stealing Steam accounts from players
    A convincing fake FACEIT verification page is stealing Steam accounts by using a fake login window that looks completely legitimate.  ( 24 min )
  • Open

    Infosec News Nuggets — June 12, 2026
    Microsoft June 2026 Patch Tuesday Fixes 6 Zero-Days, 200 Flaws Microsoft’s June 2026 Patch Tuesday addressed a staggering 200 vulnerabilities, including five publicly disclosed zero-days and one being actively exploited in the wild. Among the most severe is CVE-2026-45657, a wormable Windows Kernel RCE rated CVSS 9.8 that allows remote, unauthenticated attackers to execute code […] The post Infosec News Nuggets — June 12, 2026 appeared first on AboutDFIR - The Definitive Compendium Project.
  • Open

    IEEE Victoris 4.0 — CTF 2025 — Quals DFIR Challenges
    No content preview
    DVWA Cheat Sheet (Low & Medium)
    No content preview
    How I Built a SOAR Automation in Microsoft Sentinel That Responds to Attacks Without a Single Click
    No content preview
    Six levels, one lesson: LLMs cannot keep a secret
    No content preview
    Recovering a Forgotten Password in a Self-Hosted n8n Docker Deployment
    Learn how to recover complete access to a self-hosted n8n Docker deployment when password reset emails fail. Continue reading on InfoSec Write-ups »
    Header Manipulation: Bypasses, Probing, and the Security Audit Nobody Does
    No content preview
    Beyond the Patch: Understanding the SonicWall SSL-VPN MFA Bypass Exposure
    No content preview
    I Simulated an SSH Brute-Force Attack on My Ubuntu Server — Here’s How Fail2Ban Stopped It
    Building a simple attack lab to understand how Fail2Ban detects and blocks repeated SSH login attempts. Continue reading on InfoSec Write-ups »

  • Open

    Drupal Core CVE-2026-9082 Active Exploitation Confirmed Within Days of Disclosure
    Sensor Intel Series: June 2026 CVE Trends
  • Open

    Global Law Enforcement Dismantles ‘AudiA6’ Crypto Laundering Network Linked to Ransomware Gangs
    Summary An international coalition of law enforcement agencies, including the U.S. DOJ, Secret Service, Europol, CBZC, and others, dismantled “AudiA6,”… The post Global Law Enforcement Dismantles ‘AudiA6’ Crypto Laundering Network Linked to Ransomware Gangs appeared first on Chainalysis.  ( 13 min )
  • Open

    Software Update Automatically Turns off Amazon Delivery Drivers’ AC During Dangerous Summer Heat
    A new software update is turning off the AC in Amazon delivery vans after 10 minutes or 30 seconds under certain conditions.
    Amazon Data Centers In Mississippi Have Already Raised Electricity Rates for Local Customers, Report Suggests
    Three Amazon data centers aren't even open yet, but local residents are already paying at least $10.60 extra per month for them, according to a new study.
    Flock Leaked Cops’ License Plate Searches via DuckDuckGo, Bing
    Flock, the automatic license plate reader (ALPR) company, exposed some of the license plate cops were looking for and the reason for doing so.
    Chatbots Keep Telling Stories About Lighthouse Keeper 'Elias Thorne'. We Might Know Why
    LLMs including ChatGPT, Gemini and Claude are obsessed with telling stories about lighthouse keepers and clockmakers, and one character named 'Elias Thorne' has made his way from chatbots to Amazon books. Researchers are trying to discover why.
  • Open

    AI Security: explanation to Exploitation || Part 1
    No content preview
    Chaining Stored XSS and CSRF in Typemill CMS: A Deep Dive into Attribute Injection
    No content preview
  • Open

    Google can be liable for false AI Overviews, court rules
    "AI can make mistakes" isn't a good enough legal defense for defamatory or incorrect AI Overviews, a German court has ruled.  ( 23 min )
    VRChat says reported data breach never happened
    We explain what data was exposed, the potential risks, and the steps you should take now.  ( 22 min )
    Children’s phones must block nude images by September, UK says
    Apple and Google have three months to block nude images on children's phones. They're not allowed to collect any data while they do it.  ( 23 min )
  • Open

    Enabling Proper PCI Testing with Internal Penetration Tests
    PCI DSS v4.0.1 made internal penetration testing more complex, bringing cloud infrastructure, SaaS apps, and build pipelines explicitly into scope. Derek Rush breaks down how to scope a compliant IPT, what to test, and what a QSA-ready deliverable actually looks like in practice.
  • Open

    Infosec News Nuggets — June 11, 2026
    ServiceNow tells customers a bug left some of their data exposed to the internet Cloud platform giant ServiceNow has notified enterprise customers that a software bug was allowing unauthenticated users to access data stored in customer instances without requiring credentials. The flaw, patched on June 5, was caused by an API endpoint configured with authentication […] The post Infosec News Nuggets — June 11, 2026 appeared first on AboutDFIR - The Definitive Compendium Project.

  • Open

    University of Nottingham - 454,635 breached accounts
    In June 2026, the University of Nottingham was the target of a cyber attack, later linked to a ShinyHunters "pay or leak" extortion campaign. Tens of gigabytes of data were subsequently published online and included 455k unique email addresses along with extensive personal information including names, addresses, phone numbers, ethnicities, disabilities, passport numbers and information relating to academic enrolments and fee payments. In a post about the incident, the university advised that the breach affected both "current students, and alumni".
  • Open

    Ron Deibert Speaks About “Greek Watergate”
    Citizen Lab director Ron Deibert gave a keynote speech about the Greek spyware scandal at an event hosted by Eteron think tank in Athens in May. The post Ron Deibert Speaks About “Greek Watergate” appeared first on The Citizen Lab.
  • Open

    Weekly Threat Bulletin – June 10th, 2026
    These are the top threats you should know about this week.
  • Open

    Free Spotify Premium hacks on social media are spreading infostealers
    Cybercriminals are turning TikTok and Instagram Reels into malware delivery platforms, using free software tutorials to spread infostealers.  ( 22 min )
    Microsoft’s biggest-ever Patch Tuesday fixes 206 bugs, including 3 zero-days
    June 2026 is the largest Patch Tuesday in history, fixing 206 vulnerabilities and three publicly disclosed zero-days.  ( 22 min )
    88% of people struggle to tell what’s real online
    As AI-generated scams, deepfakes, and impersonation spread, a new Malwarebytes report finds people increasingly unsure what to trust online.  ( 22 min )
  • Open

    Turn specs into evals for any agent with ASSERT
    Adaptive Spec-driven Scoring for Evaluation and Regression Testing (ASSERT) is an open-source framework for converting natural language behavior requirements into executable evaluations of AI models and agents. The post Turn specs into evals for any agent with ASSERT appeared first on Microsoft Security Blog.
  • Open

    Scientists Just Accidentally Discovered a Strange, Hidden Rule of Human Nature
    Researchers report a "serendipitous" discovery while watching videos of crowds: an inexplicable bias toward counterclockwise turning that may be rooted in biology.
    Podcast: Google Employees Meme About How Bad Their AI Is
    Memes at Google; Microsoft wants to make its new AI assistant addictive; and manipulating Reddit.
    Cops Keep Getting Arrested for Using Flock to Stalk People
    There have been more than a dozen cases around the country where police use Flock to obsessively and illegally stalk people.
  • Open

    AI Security at Machine Speed: A Roadmap for Modern AppSec
    With AI API calls set to grow 1,000x by 2027, you need a roadmap to secure your enterprise against agentic threats.
  • Open

    Infosec News Nuggets — June 10, 2026
    Self-replicating Miasma worm hits 73 Microsoft GitHub repositories in supply chain attack The Miasma worm has reached Microsoft’s own GitHub repositories, forcing GitHub to disable 73 repos across Azure, Azure-Samples, Microsoft, and MicrosoftDocs after the worm planted malicious code designed to harvest developer credentials. The attack exploited previously compromised contributor credentials — the same account […] The post Infosec News Nuggets — June 10, 2026 appeared first on AboutDFIR - The Definitive Compendium Project.

  • Open

    Chainalysis and the Korean National Police Agency (KNPA) Sign MoU to Strengthen Virtual Asset Investigation Capabilities
    In April 2026, Chainalysis signed a Memorandum of Understanding (MoU) with the Korean National Police Agency (KNPA) to deepen cooperation… The post Chainalysis and the Korean National Police Agency (KNPA) Sign MoU to Strengthen Virtual Asset Investigation Capabilities appeared first on Chainalysis.  ( 11 min )
    체이널리시스와 대한민국 경찰청(KNPA), 디지털 자산 수사 역량 강화를 위한 양해각서(MoU) 체결
    오늘 체이널리시스는 대한민국 경찰청(KNPA)과 디지털 자산 범죄 수사 협력을 강화하기 위한 양해각서(MoU)를 체결했습니다. 이번 협약은 교육, 인증, 실무형 수사 프로그램… The post 체이널리시스와 대한민국 경찰청(KNPA), 디지털 자산 수사 역량 강화를 위한 양해각서(MoU) 체결 appeared first on Chainalysis.  ( 11 min )
    The Hidden Code Problem: How Unverified Smart Contracts Are Becoming a Preferred Target for Attackers
    Summary In the last six months, at least $36.7 million has been stolen from protocols whose source code was never… The post The Hidden Code Problem: How Unverified Smart Contracts Are Becoming a Preferred Target for Attackers appeared first on Chainalysis.  ( 14 min )
  • Open

    Submission to the Standing Senate Committee on National Security, Defence and Veterans Affairs of Bill C-8
    On May 25, senior research associate Kate Robertson appeared before SECD to testify on Bill C-8. The post Submission to the Standing Senate Committee on National Security, Defence and Veterans Affairs of Bill C-8 appeared first on The Citizen Lab.
  • Open

    Black Hat Stories | Jessica Oppenheimer, Director, SOC Integrations, Splunk Security
    No content preview
  • Open

    The June 2026 Security Update Review
    I’ve made it through Pwn2Own Berlin, had a little vacation, and now I’m back for Patch Tuesday. Microsoft and Adobe didn’t disappoint. In fact, they have heralded my return with the largest Patch Tuesday release ever. Thanks? Take a break from your regularly scheduled activities and let’s take a look at the latest security patches from Adobe and Microsoft. If you’d rather watch the full video recap covering the entire release, you can check it out here: Adobe Patches for June 2026 For May, June released 11 bulletins addressing 123 unique CVEs in Adobe Acrobat Reader, ColdFusion, Experience Manager, Experience Manager Forms, InDesign, InCopy, Substance 3D Sampler, Content Credentials SDK, Dreamweaver, Format Plugins, and Adobe Campaign Classic. A total of 11 of these CVEs were reported thro…
  • Open

    Reconstructing AI activity in investigations
    Learn how to investigate AI activity in Microsoft 365 Copilot and Azure AI services using a structured, telemetry-driven approach. This playbook helps security teams reconstruct events, assess data exposure, and detect potential threats faster. The post Reconstructing AI activity in investigations  appeared first on Microsoft Security Blog.
  • Open

    No Way Out? C2 Through AWS Data Perimeter via Bedrock-AgentCore - Dan Gansel
    No content preview
  • Open

    FCC Wants to Kill Burner Phones By Forcing Telecoms to Get All Customers’ IDs
    The FCC wants to legally force telecoms to collect new and renewing customers’ government issued identity number and physical address, impacting everyone from the privacy-conscious to domestic abuse survivors. “We never thought that would happen here.”
    Judge Learns Lawyers on Both Sides of Case Used AI, Cancels Trial, Kicks Everyone Off the Case
    When two AIs argue against each other, the legal system loses.
    'Sloppenheimer:' Amazon Employees Mock the Company’s AI on Slack
    Amazon employees have a Slack channel for memes where the mock and commiserate about the company’s faulty AI coding product.
  • Open

    Meta’s face-recognition code raises new concerns about smart glasses
    As smart glasses become more capable, concerns about face recognition, covert recording, and biometric surveillance are growing.  ( 23 min )
    Scammers love Meta, according to Lloyds Bank
    Facebook, Instagram, and WhatsApp account for more than two thirds of fraud reports made by Lloyds customers.  ( 23 min )
    Update Chrome: Google patches actively exploited vulnerability and 73 others
    Google's latest Chrome update fixes 74 security vulnerabilities, including one under active attack.  ( 22 min )
  • Open

    Mythos Doesn't Deploy Itself
    AI is raising the ceiling for skilled researchers and flooding bug bounty programs with polished but inaccurate submissions at the same time. Both things are true, and the reconciling variable is the harness built around the model and the expertise of the person driving it.
  • Open

    Infosec News Nuggets — June 9, 2026
    Critical Check Point VPN Flaw Exploited to Bypass Passwords in IKEv1 Setups — Check Point disclosed active exploitation of CVE-2026-50751 (CVSS 9.3), a logic flaw in certificate validation affecting Remote Access VPN and Mobile Access deployments using the deprecated IKEv1 protocol. The bug lets an unauthenticated remote attacker establish a VPN session without a valid […] The post Infosec News Nuggets — June 9, 2026 appeared first on AboutDFIR - The Definitive Compendium Project.

  • Open

    Extending LLVM's BOLT-based Binary Analyser to Validate Stack Variable Initialisation
    The Open Source Technology Improvement Fund (OSTIF) commissioned Quarkslab to extend the BOLT-based static binary analyser in LLVM to support additional compiler flags for security hardening. This work resulted in the first iteration of a scanner for validating the implementation of -ftrivial-auto-var-init.
  • Open

    You Used to Call Me On My Shell Phone | Jacob Swinsinski
    No content preview
  • Open

    ICYMI: May 2026 @AWS Security
    Read all about the latest AWS security features, compliance updates, and hands-on resources in our new, monthly digest posts. You’ll find expert blog posts, new service capabilities, code samples, and workshops. AWS Security Blog posts This month’s AWS Security Blog posts covered AI security, network protection, identity management, compliance frameworks, and supply chain security. Read […]
    Operationalizing AWS security: A maturity roadmap
    Enabling security tooling is the starting point. Making it operational—where findings drive decisions, response times are measurable, and your security posture improves week over week—is where most organizations struggle. This blog post provides a phased maturity roadmap for organizations that have already enabled AWS Security Hub and Amazon GuardDuty. These two services form the foundation […]
  • Open

    This Company Will Add Phone, AirPod, and Smartwatch Trackers to License Plate Readers
    SignalTrace “links devices that regularly travel together, correlating them to license plate.” It is a surveillance product that will sweep up and add all sorts of Bluetooth and other data to license plate readers, linking specific devices—and people—to cars.
    Microsoft Hacked to Deliver Malware to Claude and Gemini Users
    Microsoft took the highly unusual step of shutting down more than 70 of its own GitHub repositories after hackers pushed malware that would steal credentials from AI coding agent users.
  • Open

    AI brands as bait: How threat actors are using the AI hype in social engineering
    As threat actors operationalize AI to accelerate attacks, they are also leveraging the wider global interest around AI itself as a social engineering lure. The post AI brands as bait: How threat actors are using the AI hype in social engineering appeared first on Microsoft Security Blog.
  • Open

    Americans lost nearly $900 million to AI-powered scams, FBI says
    Deepfakes, voice cloning, and other AI-powered scams cost Americans nearly $900 million in 2025, says the 2025 FBI Internet Crime Report.  ( 22 min )
    Pirated PC games are delivering password-stealing malware
    Cybercriminals are hiding malware in cracked and repacked games, infecting more than 400,000 devices worldwide.  ( 24 min )
    A week in security (June 1 – June 7)
    A list of topics we covered in the week of June 1 to June 7 of 2026  ( 21 min )
  • Open

    Infosec News Nuggets — June 8, 2026
    New HTTP/2 Bomb Vulnerability Allows Remote DoS on NGINX, Apache, IIS, Envoy & Cloudflare — Security researchers at Calif have disclosed a novel denial-of-service technique, dubbed the HTTP/2 Bomb, that weaponizes two well-known mechanisms — HPACK header compression and Slowloris-style connection holding — in a previously unseen combination. Rather than stuffing large values into the […] The post Infosec News Nuggets — June 8, 2026 appeared first on AboutDFIR - The Definitive Compendium Project.
  • Open

    Your Origin Server Might Be Your Most Expensive Decision
    No content preview

  • Open

    Get One Step Ahead at Black Hat 🚀
    No content preview
  • Open

    Baker Distributing - 102,935 breached accounts
    In May 2026, the HVAC/R wholesale distributor Baker Distributing Company was added to the ShinyHunters data extortion group's "pay or leak" site. In early June, the group publicly published data they claimed had been obtained from Baker's SharePoint and Salesforce infrastructure including 103k unique email addresses along with names, physical addresses, phone numbers and tickets relating to the company's HVAC contractor customer base. The exposed data was largely corporate contact and support information with limited sensitivity.

  • Open

    📖 [The CloudSecList] Issue 341
    📖 [The CloudSecList] Issue 341 was originally published by Marco Lancini at CloudSecList on June 07, 2026.
  • Open

    JHT Course Launch! Windows Maldev 6
    No content preview

  • Open

    AI Beyond Triage and Hunting | Chris Botelho
    No content preview
  • Open

    Building secure B2C applications with fine-grained access control using Amazon Cognito and Amazon Verified Permissions
    Modern web applications require robust security controls to protect user data and application resources. Authentication and authorization are two fundamental pillars of application security that answer critical questions: Who are you? and What are you allowed to do? Implementing these controls correctly can be challenging for developers, especially when building data-intensive applications with frameworks like […]
  • Open

    Securing CI/CD in an agentic world: Claude Code Github action case
    Microsoft Threat Intelligence identified a prompt injection pathway in Claude Code GitHub Action that allowed access to workflow secrets under specific conditions. This research examines the attack chain, responsible disclosure process, Anthropic's mitigation, and guidance for securing AI-powered CI/CD workflows. The post Securing CI/CD in an agentic world: Claude Code Github action case appeared first on Microsoft Security Blog.
  • Open

    Inside the Black Hat community 💻
    No content preview
  • Open

    Popping Root on UniFi OS Server: Unauthenticated RCE Chain Detection & Analysis
    A three-part vulnerability chain in UniFi OS Server lets an unauthenticated attacker bypass the auth gateway, hit a command injection sink, and escalate to root in a single request. Bishop Fox confirmed the chain end to end and breaks down the attack, the impact, and how to detect it safely.
  • Open

    Infosec News Nuggets — June 5, 2026
    Hackers Spied on a Stock Exchange Executive’s Outlook Mailbox for Five Months Unknown attackers spent at least five months quietly inside the Outlook mailbox of a senior executive at a major global stock exchange, exfiltrating the inbox in small, repeated batches and routing the stolen data through Dropbox and OneDrive so the traffic blended in […] The post Infosec News Nuggets — June 5, 2026 appeared first on AboutDFIR - The Definitive Compendium Project.
  • Open

    AI: Threat, tool, or both?
    Public concern about AI is rising. We look at what's driving it, and why cybersecurity occupies a unique place in this debate.  ( 23 min )
  • Open

    BCD Travel - 396,313 breached accounts
    In May 2026, the corporate travel management company BCD Travel was claimed as a victim of the ShinyHunters "pay or leak" extortion campaign. Data allegedly obtained from BCD was subsequently published publicly in early June and contained 396k unique email addresses. Other exposed data included names, addresses, phone numbers, job titles and employer names, spanning a variety of different data sets including leads, internal staff and support tickets.

  • Open

    From prompt to pwned: chaining LLM and web bugs to Admin
    During a Red Team exercise we were able to chain multiple LLM and web-based vulnerabilities to achieve admin account takeover from a low-privileged account. Trusting the LLM turned out to be the first falling domino of a long chain of events that lead to complete compromise. In this article we describe how it went down.
  • Open

    Amazon Cognito unlocks advanced capabilities with next-generation infrastructure
    Amazon Cognito recently introduced high-throughput performance for demanding workloads, customer-managed keys for full control over data encryption at rest, and multi- Region replication for business continuity improvement. These capabilities were made possible through a next-generation storage infrastructure designed for extensibility and scale. To deliver this, we migrated hundreds of millions of user profiles, and you […]
    Gain visibility into DDoS attacks with flow logs in AWS Shield Advanced
    Reconstructing distributed denial of service (DDoS) attack traffic used to mean combining data from multiple sources after the fact. AWS Shield Advanced attack flow logs change that—they capture traffic metadata during attacks so you can pinpoint sources, verify mitigations, and feed your existing analysis pipelines. Shield publishes logs to Amazon Simple Storage Service (Amazon S3), […]
    Customize federated sign-in with new Amazon Cognito Lambda trigger
    You can use Amazon Cognito user pools to add sign-up and sign-in functionality to your web and mobile applications. You can authenticate users directly with Amazon Cognito managed accounts using passwords, passwordless flows, or custom authentication flows, or let users federate in through external identity providers (IdP) using SAML, OpenID Connect, or social providers such […]
  • Open

    Black Hat Europe 2025 | From Live Exploitation to Zero-Day Discovery: Investigating Attacks on Gogs
    No content preview
    Black Hat Europe 2025 | Network Operations Center (NOC) Report
    No content preview
    Black Hat Europe 2025 | Weaponizing Image Scaling Against Production AI Systems
    No content preview
  • Open

    Updating the taxonomy of failure modes in agentic AI systems: What a year of red teaming taught us
    A surge in real-world attacks against agentic AI systems is reshaping how we think about risk. Based on 12 months of red teaming, this update introduces seven new failure modes, from supply chain compromise to goal hijacking, and the practical mitigations teams need now. The post Updating the taxonomy of failure modes in agentic AI systems: What a year of red teaming taught us  appeared first on Microsoft Security Blog.
  • Open

    NSDI '26 - Geminet: Learning the Duality-based Topology-Agnostic Update Operator for Lightweight...
    No content preview
    NSDI '26 - Skyline: A Cloud Centric Internet Monitoring Engine
    No content preview
  • Open

    BIG SHOW TODAY & AI vibes
    No content preview
  • Open

    Putting CLIMATE into Practice: Building an Inventory Management Plan
    No content preview
  • Open

    The $100 Million Crypto “Looksmaxxing” Boom: How Chinese Cartel Suppliers Pivoted to the Gray-Market Peptide Ecosystem
    Summary A $100 Million Shadow Economy: The on-chain gray-market peptide industry has experienced a breakout, surging past a $100 million… The post The $100 Million Crypto “Looksmaxxing” Boom: How Chinese Cartel Suppliers Pivoted to the Gray-Market Peptide Ecosystem appeared first on Chainalysis.  ( 17 min )
  • Open

    Travel scams are everywhere. Here’s how to avoid them
    Learn how to spot travel scams, avoid risky bookings, and keep your personal information out of the wrong hands.  ( 22 min )
    Meta’s AI support bot happily handed Instagram accounts to hackers
    Hackers convinced an AI support bot to hand over Instagram accounts by changing recovery email addresses.  ( 23 min )
  • Open

    Infosec News Nuggets — June 4, 2026
    The Worst Hacks and Breaches of 2026 (So Far) Halfway through what’s shaping up to be a brutal year for cybersecurity, a comprehensive roundup catalogs the most damaging digital incidents of 2026, including DOGE’s alleged upload of a live Social Security database to an unsecured server, Iranian state-backed hackers remotely wiping tens of thousands of […] The post Infosec News Nuggets — June 4, 2026 appeared first on AboutDFIR - The Definitive Compendium Project.

  • Open

    Black Hat Europe 2025 | The Post-NVD Era: A Call for Global CVE Decentralization
    No content preview
    Why leaders in cybersecurity keep coming back to Black Hat
    No content preview
  • Open

    DentaQuest - 2,553,599 breached accounts
    In May 2026, the dental benefits administrator DentaQuest was the target of a ShinyHunters "pay or leak" extortion campaign that resulted in the group publicly publishing hundreds of gigabytes of data allegedly obtained from the company. The data included 2.6M unique email addresses along with names, addresses and phone numbers. Much of the data appeared in healthcare enrollment files (ASC X12 transaction sets) with some containing Medicaid IDs, while additional data appeared in member records and related files. DentaQuest acknowledged "a cybersecurity incident involving unauthorized access to a limited portion of our network", and advised they had contained the attack and mitigated the threat.
  • Open

    Topic Bridge
    CASI leaderboard shifts, and two incidents where AI was handed the keys.
    Weekly Threat Bulletin – June 3rd, 2026
    These are the top threats you should know about this week.
  • Open

    NSDI '26 - Heuristic Analysis from Source Code via Symbolic-Guided Optimization
    No content preview
  • Open

    "Practical Android Software Protection in the Wild" - An Appetizer
    This article describes the main software protection techniques used in Android applications, organized around a taxonomy covering environment checks, obfuscation, and program loading abuse. It presents the results of a large-scale analysis of nearly 2.5 million Android apps, studying how widely these protections are adopted across different markets, app categories, and malware samples.
  • Open

    We found this fake-invoice campaign while scammers were still building it
    Invoices pretending to be from Amazon, PayPal, and others reveal how criminals use fear and phone calls to steal money and devices.  ( 25 min )
    Keep getting calls from questionable numbers? Meet Scam Number Check
    Scam Number Check lets you quickly check whether a number has been linked to scams before you call back, share information, or send money.  ( 21 min )
    Infostealers are becoming the go-to phishing payload
    Cybercriminals prefer infostealers to traditional phishing techniques because they reduce friction, scale well, and are widely available.  ( 22 min )
  • Open

    Are ANY hacking scenes actually good?
    No content preview
  • Open

    Otto Support - Testing MCP Servers
    MCP servers introduce a new attack surface, but the security fundamentals are familiar. In this final otto-support post, we use nmap, a Nuclei template, and MCP Inspector to discover, enumerate, and exploit an authorization gap without ever touching an LLM.
  • Open

    Optimize AI Inference: Real-Time NodeBalancers Metrics for AI Workloads
    No content preview
  • Open

    Agentic Payments Cross the Threshold: Inside x402’s Path to Meaningful Adoption
    This blog is a preview of our report, “The New Rails: How Digital Assets Are Reshaping the Foundations of Finance.”… The post Agentic Payments Cross the Threshold: Inside x402’s Path to Meaningful Adoption appeared first on Chainalysis.  ( 14 min )
    OFAC Sanctions Nobitex and Major Iranian Cryptocurrency Exchanges in Sweeping Evasion Crackdown
    Summary The Department of the Treasury’s Office of Foreign Assets Control (OFAC) designated four major Iranian cryptocurrency exchanges: Nobitex, Bitpin,… The post OFAC Sanctions Nobitex and Major Iranian Cryptocurrency Exchanges in Sweeping Evasion Crackdown appeared first on Chainalysis.  ( 11 min )
  • Open

    Preinstall to persistence: Inside the Red Hat npm Miasma credential-stealing campaign
    A large-scale npm supply chain attack compromised over 90 versions of @redhat-cloud-services packages, silently infecting CI/CD environments and developer systems. The malicious code steals credentials from GitHub, cloud platforms, and local machines, then spreads like a worm by republishing trusted packages. Discover how the attack works, what data is at risk, and the steps you can take to protect your organization. The post Preinstall to persistence: Inside the Red Hat npm Miasma credential-stealing campaign appeared first on Microsoft Security Blog.
  • Open

    When One Vulnerability Cascades Across Cloud Infrastructure - Albin Vattakattu & Ryan Nolette
    No content preview
    Barbarians at the Gate: Visualizing and Blocking SDLC Infrastructure Threats with SITF - S Berkovich
    No content preview
    Transforming Security Incident Metadata to Security Outcomes - Cydney Stude & Steve de Vera
    No content preview
    A Hero’s Guide to Building a Cloud Security Program Without a 20-Person Guild - Steve Turner
    No content preview
    Schrödinger’s Detection: Finding the "Zombie" Rules in Your SIEM - Gowthamaraj
    No content preview
    Beyond the Checkbox: What Breaks When You Actually Stress-Test Cloud Incident Response - M Harvey
    No content preview
    Do Apps Have Imposter Syndrome? Unmasking Token Theft Campaigns - Shahar Dorfman & Sapir Federovsky
    No content preview
    One Architectural Sin, Two Clouds, and a Universal Attack Technique for Data Hijacking - Yahav
    No content preview
    Artificial Intelligence 🤝 Natural Stupidity - Brandon Sherman
    No content preview
    Beyond the Perimeter: Retrofitting VPC-SC at Enterprise Scale - Priya Puranik & Akshay Mahajan
    No content preview
    Data Perimeters: Beyond the Marketing - Matt Luttrell
    No content preview
    Paying More for Worse Security: An AWS Marketplace Horror Story - Corey Quinn
    No content preview

  • Open

    NSDI '26 - Co-Designing Traffic Control with NVMe-oF for Disaggregated Storage: A Comparative Study
    No content preview
    NSDI '26 - A Composable Emulation Framework for Whitebox Switches
    No content preview
    USENIX Security '24 - Inference of Error Specifications and Bug Detection Using Structural...
    No content preview
    NSDI '26 - Defending against Traffic Analysis Attacks with Flexible In-Network Obfuscation
    No content preview
  • Open

    Black Hat Europe 2025 | You Win Some, You CheckSum: A Kerberos Delegation Vulnerability
    No content preview
  • Open

    Identify unused AWS KMS keys and prevent accidental key deletions
    As you scale your use of Amazon Web Services (AWS), managing KMS keys becomes increasingly important. Whether you manage a handful of keys or thousands across multiple AWS accounts and AWS Regions, there’s often a need to audit key usage to help you meet compliance requirements, evaluate your risk posture, and optimize key management costs. […]
    Secure multi-tenant AI agents with Amazon Bedrock AgentCore resource-based policies
    Software as a service (SaaS) providers building AI-powered applications on Amazon Bedrock AgentCore often need to serve multiple tenants with distinct security requirements from a shared infrastructure. Some tenants require cross-account access from their own Amazon Web Services (AWS) accounts, while others mandate that traffic stay within a private virtual private cloud (VPC) for regulatory […]
  • Open

    Microsoft Build 2026: Securing code, agents, and models across the development lifecycle
    Discover how Microsoft enables fast, secure AI development with MDASH and new security capabilities. The post Microsoft Build 2026: Securing code, agents, and models across the development lifecycle appeared first on Microsoft Security Blog.
  • Open

    I made AI agents apply for my Security Team. Then I gave the agents access to AWS. - Cole Horsman
    No content preview
    Observing Escalation Paths in Kubernetes - William Taylor
    No content preview
  • Open

    Highlights from the Akamai India Partner Summit 2026
    No content preview
  • Open

    Infosec News Nuggets — June 2, 2026
    OpenAI Codex Authentication Tokens Stolen in codexui-android npm Supply Chain Attack A malicious supply chain campaign has been stealing OpenAI Codex authentication tokens through a popular npm package called codexui-android, which draws over 29,000 weekly downloads by advertising itself as a legitimate remote web UI for Codex. Unlike typical typosquatting attacks, the exfiltration code was […] The post Infosec News Nuggets — June 2, 2026 appeared first on AboutDFIR - The Definitive Compendium Project.
  • Open

    A Hacker's Way of Thinking (with Ted Harrington)
    No content preview

  • Open

    NSDI '26 - Syntra: Synthesizing Cross-Layer Controllers for Low-Latency Video Streaming
    No content preview
    NSDI '26 - Net-P4ct: Enhanced WAN Bandwidth Fair Sharing Using P4 Programmable Switches
    No content preview
    NSDI '26 - KRAKENGUARD: Towards Fine-Grained eBPF Isolation
    No content preview
    NSDI '26 - OneSidedMW: Managing Disaggregated Memory Efficiently, Flexibly, and Securely with RNIC
    No content preview
    NSDI '26 - Cost-effective and Reliable Global Internet Peering with Programmable Switches
    No content preview
    NSDI '26 - Medley: Optimizing Midgress Bandwidth for Commercial Live Streaming CDNs
    No content preview
    NSDI '26 - HeteCCL: Synthesizing Near-Optimal Collective Communication Schedules for Heterogeneous
    No content preview
    NSDI '26 - Mitigating CPU Frontend for Complex Data Plane Applications
    No content preview
  • Open

    Chilling Effects of Trump’s War on Free Speech Extend Far Beyond Campus Walls – And That’s the Point
    Citizen Lab senior research fellow Jon Penney and co-author Bruce Schneier wrote an op-ed in The Conversation about chilling effects. The post Chilling Effects of Trump’s War on Free Speech Extend Far Beyond Campus Walls – And That’s the Point appeared first on The Citizen Lab.
  • Open

    Spring 2026 SOC 1, 2, and 3 reports are now available with 188 services in scope
    Amazon Web Services (AWS) is pleased to announce that the Spring 2026 System and Organization Controls (SOC) 1, 2, and 3 reports are now available. The reports cover 188 services over the 12-month period from April 1, 2025–March 31, 2026, giving customers a full year of assurance. These reports demonstrate our continuous commitment to adhering […]
  • Open

    A Linux Backdoor is For Sale on the Dark Web
    No content preview
  • Open

    InfoSec News Nuggets — June 1, 2026
    Signal Phishing Campaign Targets Journalists and Activists to Steal Backup Recovery Keys A targeted phishing campaign is sending text messages that impersonate Signal Support, urgently requesting users paste their 64-character backup recovery key into the chat. Unlike standard account takeovers that only expose future messages, stealing the recovery key gives attackers full access to the […] The post InfoSec News Nuggets — June 1, 2026 appeared first on AboutDFIR - The Definitive Compendium Project.
  • Open

    Edmunds - 177,860 breached accounts
    In January 2026, the automotive research and car-shopping platform Edmunds was listed by the ShinyHunters hacking group as having been breached. Data purportedly obtained in the incident was later published publicly and included 178k unique email addresses, usernames, passwords, IP addresses, phone numbers and vehicle-related records.

  • Open

    Scala Security Audit
    The Scala team has partnered with the Open Source Technology Improvement Fund (OSTIF) to conduct its first security audit. This initiative aims to identify potential vulnerabilities through static and dynamic analysis and provide greater confidence in Scala. The security audit conducted by Quarkslab is particularly focused on Scala 3.

  • Open

    Atlas Menu - 63,926 breached accounts
    In May 2026, the GTA V and CS2 cheat service Atlas Menu suffered a data breach. An attacker claimed to have gained access to all Atlas systems and published the service's database to a public GitHub repository. The incident exposed 64k unique email addresses along with usernames, IP addresses, support tickets and passwords stored as bcrypt hashes.
  • Open

    📖 [The CloudSecList] Issue 340
    📖 [The CloudSecList] Issue 340 was originally published by Marco Lancini at CloudSecList on May 31, 2026.
  • Open

    ContinuumCon Teaser: solst/ice, Zack Korman, & Spencer Alessi!!
    No content preview
  • Open

    Malicious npm packages abuse dependency confusion to profile developer environments
    A dependency confusion campaign leveraged 33 malicious npm packages to collect reconnaissance data from developer and build environments. This report details the attack chain, observed tradecraft, and detection opportunities to help organizations identify and disrupt related activity. The post Malicious npm packages abuse dependency confusion to profile developer environments appeared first on Microsoft Security Blog.

  • Open

    Unmasking Romance Scams with OSINT | Mishaal Khan
    No content preview
  • Open

    Black Hat Europe 2025 | Flaw And Order: Finding The Needle In The Haystack Of CodeQL Using LLMs
    No content preview
    Black Hat Europe 2025 | A crash course in revealing insecure blind spots for DoS & DDoS
    No content preview
  • Open

    Microsoft is named a Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection
    Microsoft is named a Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection. The post Microsoft is named a Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection appeared first on Microsoft Security Blog.
    Typosquatted npm packages used to steal cloud and CI/CD secrets
    The Mini Shai-Hulud campaign used malicious npm packages to target cloud and CI/CD credentials across developer environments. This report details the attack chain, detection opportunities, and mitigation guidance to help organizations identify and disrupt related activity. The post Typosquatted npm packages used to steal cloud and CI/CD secrets appeared first on Microsoft Security Blog.
  • Open

    Researchers Uncover Espionage in Mobile Networks
    Swantje Lange spoke with the Hasso Plattner Institut about sophisticated surveillance campaigns being used to exploit mobile networks. The post Researchers Uncover Espionage in Mobile Networks appeared first on The Citizen Lab.
  • Open

    Looting UniFi Controllers: Detecting and Weaponizing CVE-2026-22557
    A CVSS 10.0 path traversal in UniFi Network Application lets unauthenticated attackers read controller backups, extract credentials, and take over every managed device on the network. Bishop Fox breaks down the attack paths, the preconditions, and a safe detection tool to check your exposure.
  • Open

    InfoSec News Nuggets – 05/29/2026
    Carnival Cruise Confirms Data Breach Affecting Nearly 6 Million People Carnival Corporation, the world’s largest cruise line operator, began notifying nearly 6 million customers this week that their personal data was stolen in an April breach after attackers gained access to an employee account through a social engineering attack. The stolen data varies by individual […] The post InfoSec News Nuggets – 05/29/2026 appeared first on AboutDFIR - The Definitive Compendium Project.
  • Open

    Payload Podcast 007 with Andy Piazza (klrgrz)
    No content preview

  • Open

    Black Hat Europe 2025 | Unveiling System Management Mode Memory Corruption Vulnerability Via Fuzzing
    No content preview
    Black Hat Stories | Ari Herbert-Voss, CEO and Founder of RunSybil
    No content preview
  • Open

    Why and how to migrate to a Transit Gateway-attached AWS Network Firewall
    AWS Network Firewall now supports native attachment to AWS Transit Gateway. Customers commonly use Transit Gateway to route traffic from Amazon Virtual Private Cloud (Amazon VPC) networks to a centralized inspection VPC (a VPC dedicated to hosting firewall endpoints for traffic inspection) where their network firewall endpoints are deployed. This centralized deployment model reduces the […]
    Simplifying policy management with URL and Domain Category filtering on AWS Network Firewall
    Network administrators face a persistent challenge: maintaining domain blocklists and allowlists that keep pace with the internet. New websites and services emerge daily, and keeping these lists current requires constant manual updates that leave gaps in coverage. This challenge intensifies when managing access to rapidly evolving categories like AI services, where new tools launch on […]
  • Open

    Charter - 4,851,517 breached accounts
    In May 2026, the telecommunications company Charter Communications (the parent company behind the consumer broadband and cable brand Spectrum) was named by the ShinyHunters group in a "pay or leak" extortion campaign. The group later published the data, which exposed 4.9M unique email addresses along with names, phone numbers and physical addresses. A subset of approximately 85k records originating from an internal employee directory also included job titles. Charter confirmed the incident, but stated that no sensitive personal information or customer proprietary network information (CPNI) was exfiltrated.
    Kemper - 269,299 breached accounts
    In April 2026, the American insurance holding company Kemper Corporation was named by the ShinyHunters ransomware group in a "pay or leak" extortion campaign. The attackers allegedly accessed Kemper's Salesforce environment via social engineering as part of a broader campaign targeting hundreds of organisations using the same method. The group later published tens of gigabytes of data they claimed included internal directory data, Salesforce records and Stripe payment logs. Among the 269k unique email addresses were names, phone numbers, physical addresses and partial payment card data including the last 4 digits, expiry dates and card brands. Kemper confirmed the incident and stated they had engaged third-party cybersecurity experts and notified law enforcement.
  • Open

    Consistent Protections Without Compromise: Akamai’s WAF Is Now on AWS Marketplace
    No content preview

  • Open

    The Small Model Cliff
    CASI Leaderboard, Bias Jailbreak, and Three Coordinated Supply Chain Incidents
    Weekly Threat Bulletin – May 27th, 2026
    These are the top threats you should know about this week.
  • Open

    Google served me Malware
    No content preview
  • Open

    The New Compliance Floor: Organizations are Adopting Stronger Than Ever Monitoring Practices
    This blog is a preview of our report, “The New Rails: How Digital Assets Are Reshaping the Foundations of Finance.”… The post The New Compliance Floor: Organizations are Adopting Stronger Than Ever Monitoring Practices appeared first on Chainalysis.  ( 15 min )
    U.K. Sanctions 18 Entities and Persons for Evading Russian Trade Blockades
    Summary The U.K.’s Foreign, Commonwealth and Development Office (FCDO) sanctioned 18 cryptocurrency exchanges, payment providers, and individuals for helping Russia… The post U.K. Sanctions 18 Entities and Persons for Evading Russian Trade Blockades appeared first on Chainalysis.  ( 12 min )
  • Open

    Distributed AI Inference: Why Placement Is the New Bottleneck
    In real AI systems, bottlenecks don't disappear, they move. Learn about why inference placement, not raw compute, is the decisive infrastructure question.
  • Open

    Mytheresa - 84,108 breached accounts
    In April 2026, the luxury fashion e-commerce platform Mytheresa was listed as a victim of the ShinyHunters "pay or leak" extortion group. After the ransom deadline passed, the group publicly released the data which contained 84k unique email addresses. The exposed data also included names, phone numbers, physical addresses, purchases and partial credit card data including card type, last 4 digits and expiry date.

  • Open

    Ameriprise - 502,597 breached accounts
    In March 2026, the financial services firm Ameriprise Financial was named by the ShinyHunters group in a "pay or leak" extortion campaign. The group claimed possession of more than 200GB of compressed data exfiltrated from Ameriprise's Salesforce environment and internal SharePoint infrastructure, and subsequently published the data after negotiations allegedly failed. The published data contained 500k unique email addresses as well as names, phone numbers, physical addresses and employer information. In their disclosure to state attorneys general, Ameriprise reported 47,876 affected people; the larger email address population represents contacts from Ameriprise's broader operational systems, including internal staff. Ameriprise further advised that they have "implemented heightened monitoring of your account(s) to include enhanced identity verification procedures".
  • Open

    Payload Podcast 007 with Andy Piazza (klrgrz)
    No content preview
  • Open

    Welcoming the AWS Customer Incident Response Team
    May 26, 2026: This post was originally published in July 2022. It has been updated to reflect current engagement options, new threat intelligence resources such as the Threat Technique Catalog for AWS (TTC), additional open-source tools, and the distinction between AWS CIRT support and the AWS Security Incident Response managed service. Welcome back, or welcome […]
    Well-architected best practices for software supply chain security
    There have been multiple notable supply chain attacks using the npm Registry since September: Shai-Hulud, Chalk/Debug, one abusing tea.xyz tokens, and recently axios. Thanks to community efforts involving the Amazon Inspector team, the Open Source Security Foundation, and others, the affected packages were quickly flagged, which reduced the impact of these incidents. Supply chain attacks […]
  • Open

    SecTor 2025 | Grand Finale: Cutting Through the Cyber Noise
    No content preview
    SecTor 2025 | Chasing Shadows: Chronicles of Counter-Intelligence from the Citizen Lab
    No content preview
  • Open

    Introducing Password-Less Provisioning and Atomic Customization for VMs
    Akamai Cloud introduces password-less provisioning and atomic customization. Align with Zero Trust by eliminating root passwords and hardening VMs at creation.
  • Open

    Sparkplug B Protocol Fuzzing with AI Assistance
    Sparkplug B is the dominant protocol in ICS and SCADA environments, but no public security fuzzer existed for it until now. Bishop Fox used AI-assisted development to build one from scratch, covering all 9 message types, 19 data types, and 87+ field paths from the full specification.

  • Open

    Trump Wants to Tap Your Phone. Ottawa Might Let Him.
    Senior research associate Kate Robertson discusses the risks Bill C-22 poses for future data-sharing agreements with foreign law enforcement agencies. The post Trump Wants to Tap Your Phone. Ottawa Might Let Him. appeared first on The Citizen Lab.
  • Open

    Hack the Notes: Exploring Pen-Test Documentation | Christian Duncan
    No content preview

  • Open

    7-Eleven - 185,256 breached accounts
    In April 2026, 7-Eleven was the victim of a "pay or leak" extortion campaign by ShinyHunters, with the data later published that month. The incident exposed 185k unique email addresses, along with names, physical addresses, dates of birth and phone numbers. A small number of records also contained additional exposed data fields. The company later advised the breach was limited to "certain 7-Eleven systems used to store franchisee documents", a statement consistent with the exposed data.

  • Open

    📖 [The CloudSecList] Issue 339
    📖 [The CloudSecList] Issue 339 was originally published by Marco Lancini at CloudSecList on May 24, 2026.

  • Open

    OFAC and Crypto Crime: Every OFAC Specially Designated National with Identified Cryptocurrency Addresses
    As far back as the early 1800s, the U.S. Department of the Treasury has issued economic sanctions to achieve foreign… The post OFAC and Crypto Crime: Every OFAC Specially Designated National with Identified Cryptocurrency Addresses appeared first on Chainalysis.  ( 28 min )
  • Open

    Detecting CVE-2026-0265 at Scale: PAN-OS CAS Authentication Bypass
    CVE-2026-0265 lets unauthenticated attackers forge a JWT and log in as any trusted user on CAS-enabled PAN-OS deployments. Bishop Fox built a detection tool that returns a definitive verdict from a single anonymous request, and breaks down exactly how the bug works and what to do about it.
    CVE-2026-27886: Unauthenticated Boolean-Oracle Exfiltration of Administrator Secrets in Strapi
    A sanitization bypass in Strapi 4.0.0 through 5.36.1 lets unauthenticated attackers extract an admin's password reset token character by character and take over the account. With over 20,000 internet-facing hosts exposed, Bishop Fox breaks down how the exploit works and how to remediate it.
  • Open

    Deserialization payloads for exploits w/ GO-based .NET & Java gadget generation | Jonathan Peterson
    No content preview

  • Open

    Decentralized Threat: Stealthy P2P Cryptominer Targeting Ollama Endpoints
    The Akamai SIRT uncovered a custom P2P Trojan masquerading as system activity. Learn how to detect and mitigate this stealthy Go-based cryptominer.
    Secure Identity at the Edge: Akamai Partners with Auth0
    The Akamai and Auth0 partnership secures identity at the edge by combining edge intelligence and adaptive authentication to stop fraud and enhance user trust.
    CVE-2026-9082: Mitigating a Critical SQL Injection Vulnerability in Drupal
    Learn how the complex Drupal SQLi vulnerability (CVE-2026-9082) exploits PostgreSQL environments and its data theft risks — and how to ensure you’re protected.
  • Open

    AWS KY3P report now available for third-party supplier due diligence
    We’re excited to announce that Amazon Web Services (AWS) has completed the S&P Global Know Your Third Party (KY3P) assessment of its security posture. This assessment demonstrates our continued commitment to meet the heightened expectations of cloud service providers. Customers can now use the AWS KY3P assessment to reduce their supplier due diligence burden. KY3P, […]
    Automating identity lifecycle and security with AWS Directory Service APIs
    Managing identities and access across complex environments has become more critical than ever. AWS Directory Service for Managed Microsoft Active Directory, also known as AWS Managed Microsoft AD, has added new capabilities to manage users and groups. Now, you can perform create, read, update, and delete (CRUD) operations on users and groups directly through AWS […]
  • Open

    Dragonica Lunaris - 126,293 breached accounts
    In December 2025, the European Dragonica private server Dragonica Lunaris suffered a data breach. The incident exposed 126k email addresses, usernames, dates of birth and bcrypt password hashes. The service operator confirmed the breach and advised it has since been fixed.
    Windows93 / Myspace93 - 46,105 breached accounts
    In January 2021, the parody site Windows93 suffered a data breach of the Myspace93 sub-site after a beta application was exploited to download server files. The compromised data was later leaked in June and included 46k Myspace93 accounts containing email and IP addresses, usernames and passwords stored in plain text.

  • Open

    Why Policy in Amazon Bedrock AgentCore chose Cedar for securing agentic workflows
    Agents have agency: they adapt and find multiple ways to solve problems. This autonomy creates a fundamental security challenge: the large language model (LLM) at the heart of the agent is non-deterministic, and its decisions can’t be predicted or guaranteed in advance. It can hallucinate harmful actions with complete confidence. It’s vulnerable to prompt injection […]
    AWS Security Hub Extended: Why enterprise security products should sell themselves
    Our largest security services customers started the same way every customer does – with a click. They enabled Amazon GuardDuty, Amazon Inspector, AWS WAF, and AWS Security Hub, experienced the benefits in real time, and evaluated with transparent pay-as-you-go pricing. No RFP. No six-month evaluation. No multi-year commitment up front. Our field teams played a […]
  • Open

    Weekly Threat Bulletin – May 20th, 2026
    These are the top threats you should know about this week.
  • Open

    This Is a Hold-Up: Financial Services Under Attack
    No content preview

  • Open

    Microsoft Exchange ProxyShell Scanning Doubles in April 2026 as Two Distinct Campaign Clusters Emerge
    Sensor Intel Series: April 2026 CVE Trends
  • Open

    CIRT insights: How to help prevent unauthorized account removals from AWS Organizations
    The AWS Customer Incident Response Team works with customers to help them recover from active security incidents. As part of this work, the team often uncovers new or trending tactics used by various threat actors that take advantage of specific customer configurations and designs. Understanding these tactics can help inform your architecture decisions, improve your […]
    Governing infrastructure as code using pattern-based policy as code
    Organizations often struggle to enforce security and compliance requirements consistently across their cloud infrastructure. In one environment, a workload might be deployed in an AWS Region that was never approved for that class of data. In another, a security group might allow broader access than intended. Required tags might be missing. Encryption might be assumed […]
  • Open

    CTT - 468,124 breached accounts
    In April 2026, data allegedly obtained from CTT, Portugal's national postal service, was posted to a public hacking forum. The data included 468k unique email addresses along with names, phone numbers and parcel tracking numbers which can be used to retrieve the tracking history of the parcel.

  • Open

    How OLTs may have exposed entire ISP networks
    An Optical Line Terminal (OLT) is the central device in a Fiber-To-The-Home (FTTH) network that connects and manages all customer connections, making it a critical control point in an ISP's infrastructure for delivering high speed Internet. This article uncovers how unauthenticated access to OLTs can lead to a full network takeover starting by exploiting exposed vulnerable devices, showing how to pivot into the cloud-based fleet manager using other vulnerabilities, and then compromising an ISP's entire infrastructure.
  • Open

    Addi - 34,532,941 breached accounts
    In March 2026, the Colombian fintech company Addi identified unauthorised activity on its platform and advised customers that "it is possible that your personal information may have been compromised". The "pay or leak" extortion group ShinyHunters subsequently claimed responsibility and published a large trove of personal data allegedly obtained from Addi. The data included 34M unique email addresses from credit scoring requests, credit bureau records, customer identity records and email validation logs. It also contained government issued IDs (Cédula de Ciudadanía), estimated income, socioeconomic levels, purchases and other credit-related data points.
  • Open

    I Built an AI Cybersecurity Research Factory (for CTFs & Vulnerabilities)
    No content preview
  • Open

    CVE-2026-42945: Mitigating a Critical Heap Buffer Overflow Vulnerability in NGINX
    Discover CVE-2026-42945 (NGINX Rift), a critical heap buffer overflow vulnerability. Learn about the affected versions and critical patch updates.

  • Open

    📖 [The CloudSecList] Issue 338
    📖 [The CloudSecList] Issue 338 was originally published by Marco Lancini at CloudSecList on May 17, 2026.
2026-06-15T04:20:33.763Z osmosfeed 1.15.1