> TODAY'S SUMMARY (108 articles)
Today's cybersecurity landscape highlights several significant threats and trends. AI models continue to leak sensitive corporate data, with over 13,000 exposed images identified by Glow Security. A major breakthrough in law enforcement occurred with the arrest of a ShinyHunters leader in the Netherlands, coinciding with recent high-profile hacks, including an attack on the FBI. Russian threat actor Star Blizzard has refined phishing techniques, while Citrix NetScaler is facing mass exploitation of a zero-day vulnerability (CVE-2026-88771). Apple has patched a critical zero-day flaw (CVE-2026-86950) linked to sophisticated attacks, underscoring ongoing vulnerabilities in popular software. Additionally, the Pentagon personnel agency breach affecting 3 million individuals emphasizes the persistent risk to sensitive government data.
|
// AI-powered summary generated at 16:00
Man escapes jail time after using his position to snoop on thousands of accounts
Adware is often being pre-installed on mobile devices
Amazon Bug Bounty! Great news: Amazon is now offering bounties via a security vulnerabiltiy research program
Bad news: AWS is out of scope!
When I read this I remembered that a few years ago I found persistent Cross-Site-Scripting on the AWS Console.
This post is a write up on how I found the XSS ba...
37% of workers expect the number and size of fines for their employers to increase
Weakness exploited in way Hotels.com generates vouchers
I’m excited that Feedspot ranked this blog (Embrace the Red) the number #10 pentest blog out there.
Subscribe and check-in regularly for new content related to offensive security engineering, penetration testing and red teaming.
You can also follow me on Twitter @wunderwuzzi23.
Cheers.
ISP estimates cost to UK economy of ÂŁ87bn
Sansec claims Pyongyang-sponsored attackers struck Claire’s
A few months ago we discussed the importance of performing active credential hunting for your organization.
This is to ensure clear text credentials in widely accessible locations and source code are identified before an adversary gets a hold of them.
In this post we will explore using built-in oper...
Heated debate in infosec community after calls for change in terminology
Be careful which pre-configured policies you leave on your IPsec VPN, warns the US government
Les marqueurs techniques suivants sont associés au groupe cybercriminel TA505 (voir la publication CERTFR-2020-CTI-006). Ils peuvent être utilisés à des fins de recherche de compromission dans des journaux historiques ou de détection. Mise à jour du 10 février 2021 : un nouveau rapport détaillant...
The Nova Scotia moose hunting lottery didn’t go entirely to plan this year
The Avaddon ransomware is using Excel 4.0 macros as an infection vector
The NCSC plans to provide a mix of classroom and virtual classes going forward
Researchers at vpnMentor claim fitness firm misconfigured S3 bucket
Backdoor removal asks more questions than it answers
WizCase researchers find unsecured online databases in US and Asia
Apache Guacamole is an open source remote access gateway
Educational establishments across the US have leaked millions of records since 2005, according to an analysis of public data